Description
An issue was discovered in Joomla! 3.0.0 through 3.9.24. Extracting an specifilcy crafted zip package could write files outside of the intended path.
Remediation
References
Related Vulnerabilities
Hesk Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2011-3743)
Django Unrestricted Upload of File with Dangerous Type Vulnerability (CVE-2021-31542)
Oracle JRE CVE-2018-2602 Vulnerability (CVE-2018-2602)
WordPress Plugin Coming Soon Possible Remote Code Execution (1.1.3)