Description
An issue was discovered in Joomla! 2.5.0 through 3.9.22. The folder parameter of mod_random_image lacked input validation, leading to a path traversal vulnerability.
Remediation
References
Related Vulnerabilities
WordPress Plugin YITH WooCommerce Gift Cards Security Bypass (1.3.7)
WordPress Plugin Sell Media Cross-Site Request Forgery (2.5.5)
Joomla CVE-2020-35610 Vulnerability (CVE-2020-35610)
PHP Other Vulnerability (CVE-2015-2301)
WordPress Plugin WP Custom Pages 'url' Parameter Local File Disclosure (0.5.0.1)