漏洞标题:Joomla扩展 - acymailing.com - AcyMailing Enterprise扩展(版本<11.1.0)中的未授权任意文件删除漏洞 漏洞描述:攻击者(如订阅者)可以将文件路径存储到“文件类型”自定义字段中,当该字段被清空时,AcyMailing扩展会删除该路径指向的文件。此漏洞可导致删除非上传目录下的敏感文件,例如 configuration.php 配置文件。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| acymailing.com | AcyMailing extension for Joomla | 1.0.0-11.0.5 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet