Home
MEDIUM: 4.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:A/VC:N/VI:N/VA:N/SC:L/SI:L/SA:LDefault status
unaffected
1.0.0-5.0.15
affected
Description
User provided uploads to the Easy Discuss component for Joomla aren't properly validated. Uploads are purely checked by file extensions, no mime type checks are happening.
Problem types
CWE-434 Unrestricted Upload of File with Dangerous Type
Product status
1.0.0-5.0.15
Credits
simoni
Swiss Paraplegic Research
References
stackideas.com/easydiscuss