CVE-2020-23972
gmapfp gmapfp Unrestricted Upload of File with Dangerous Type
Record summary
CVE-2020-23972 has a selected CVSS score of 7.5 (high); EIP currently links 1 catalogued exploit and 1 Nuclei template.
Description
In Joomla Component GMapFP Version J3.5 and J3.5free, an attacker can access the upload function without authenticating to the application and can also upload files which due to issues of unrestricted file uploads which can be bypassed by changing the content-type and name file too double extensions.
Exploitation context
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
gmapfpBrowse gmapfp / gmapfp | VulnCheck | Version data not supplied | |
Proofs of concept
1Catalogued exploits
ExploitDBJoomla! Component GMapFP 3.5 - Unauthenticated Arbitrary File UploadExploitDB exploitby ThelastVvVNot analyzed1 file
Nuclei templates
1ProjectDiscoveryHIGHJoomla! Component GMapFP 3.5 - Arbitrary File UploadCVSS 7.5
Joomla! Component GMapFP 3.5 is vulnerable to arbitrary file upload vulnerabilities. An attacker can access the upload function of the application without authentication and can upload files because of unrestricted file upload which can be bypassed by changing Content-Type & name file too double ext.
Impact
Successful exploitation of this vulnerability can result in unauthorized remote code execution on the affected Joomla! website.
Remediation
Apply the latest security patch or update to a patched version of Joomla! Component GMapFP 3.5 to mitigate this vulnerability.
Source: ProjectDiscovery