Description
An issue was discovered in Joomla! 3.0.0 through 3.10.6 & 4.0.0 through 4.1.0. Extracting an specifilcy crafted tar package could write files outside of the intended path.
Remediation
References
Related Vulnerabilities
Drupal Improper Authentication Vulnerability (CVE-2010-3686)
SharePoint CVE-2020-0975 Vulnerability (CVE-2020-0975)
WordPress CVE-2014-5203 Vulnerability (CVE-2014-5203)
PostgreSQL Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2018-1052)
WordPress Plugin Enable Media Replace SQL Injection and Arbitrary File Upload Vulnerabilities (2.3)