Description
Joomla! Core is prone to a vulnerability that lets attackers upload arbitrary files because the application fails to properly verify user-supplied input. An attacker can exploit this vulnerability to upload arbitrary code and run it in the context of the webserver process. This may facilitate unauthorized access or privilege escalation; other attacks are also possible. Joomla! Core versions 1.5.x ranging from 1.5.0 and up to and including 1.5.15 are vulnerable.
Remediation
References
Related Vulnerabilities
Envoy Proxy CVE-2025-30157 Vulnerability (CVE-2025-30157)
Oracle Database Server Create Session privilege issue (CVE-2021-1993)
WordPress Plugin VikRentCar Car Rental Management System Cross-Site Request Forgery (1.1.6)
WordPress Plugin WP Custom Cursors Multiple Vulnerabilities (3.0)
WordPress Plugin Yoast SEO Cross-Site Request Forgery (3.3.1)