CVE-2019-10945

CRITICAL

Joomla! < 3.9.4 - Path Traversal

Title source: rule

Description

An issue was discovered in Joomla! before 3.9.5. The Media Manager component does not properly sanitize the folder parameter, allowing attackers to act outside the media manager root directory.

Exploits (5)

exploitdb WORKING POC
by Haboob Team · pythonwebappsphp
https://www.exploit-db.com/exploits/46710
nomisec WORKING POC 24 stars
by dpgg101 · poc
https://github.com/dpgg101/CVE-2019-10945
github WORKING POC 1 stars
by Shockp · pythonpoc
https://github.com/Shockp/CVE-Exploits/tree/main/CVE-2019-10945 (joomla 3.9.4)
nomisec WORKING POC
by tayW84 · poc
https://github.com/tayW84/CVE-2019-10945----Python3
nomisec WORKING POC
by Snizi · poc
https://github.com/Snizi/CVE-2019-10945

Scores

CVSS v3 9.8
EPSS 0.8109
EPSS Percentile 99.2%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-22
Status published
Products (1)
joomla/joomla\! 1.5.0 - 3.9.4
Published Apr 10, 2019
Tracked Since Feb 18, 2026