AnyMailing Joomla Plugin is vulnerable to unauthenticated...
Critical severity
Unreviewed
Published
Mar 30, 2023
to the GitHub Advisory Database
•
Updated Apr 14, 2023
Description
Published by the National Vulnerability Database
Mar 30, 2023
Published to the GitHub Advisory Database
Mar 30, 2023
Last updated
Apr 14, 2023
AnyMailing Joomla Plugin is vulnerable to unauthenticated remote code execution, when being granted access to the campaign's creation on front-office due to unrestricted file upload allowing PHP code to be injected. This issue affects AnyMailing Joomla Plugin Enterprise in versions below 8.3.0.
References