CVE-2023-28731

All FrameworksJoomlaCWE-434CVE-2023-28731

CVE-2023-28731

State: PUBLISHED · Published: 2023-03-30 · Updated: 2025-02-11 · Assigner: NCSC.ch
Description
AnyMailing Joomla Plugin is vulnerable to unauthenticated remote code execution, when being granted access to the campaign's creation on front-office due to unrestricted file upload allowing PHP code to be injected. This issue affects AnyMailing Joomla Plugin Enterprise in versions below 8.3.0.
CWE
Affected
CVSS
References
Source
cvelistV5-main/cves/2023/28xxx/CVE-2023-28731.json