CVE-2023-28731
Description
AnyMailing Joomla Plugin is vulnerable to unauthenticated remote code execution, when being granted access to the campaign's creation on front-office due to unrestricted file upload allowing PHP code to be injected.
This issue affects AnyMailing Joomla Plugin Enterprise in versions below 8.3.0.
CWE
- CWE-20 — CWE-20 Improper Input Validation
- CWE-434 — CWE-434 Unrestricted Upload of File with Dangerous Type
Affected
- AcyMailing / Newsletter Plugin for Joomla in the Enterprise version — v=0 <8.3.0 [affected]
CVSS
- 3.1 score=9.8 severity=CRITICAL
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
References
Source
cvelistV5-main/cves/2023/28xxx/CVE-2023-28731.json