CVE-2020-37219

HIGH

Joomla com_fabrik 3.9.11 Directory Traversal via image.php

Title source: cna
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2020-37219. PoCs published by qw3rTyTy.

AI-analyzed exploit summary This exploit demonstrates a directory traversal vulnerability in Joomla! com_fabrik 3.9.11, allowing unauthorized access to files outside the intended directory via crafted HTTP requests. The PoC includes functional curl commands that successfully retrieve file listings from arbitrary directories.

Description

Joomla com_fabrik 3.9.11 contains a directory traversal vulnerability that allows unauthenticated attackers to list arbitrary files by manipulating the folder parameter. Attackers can send GET requests to the onAjax_files method with path traversal sequences to enumerate files in system directories outside the intended web root.

Exploits (1)

exploitdb WORKING POC
by qw3rTyTy · textwebappsphp
https://www.exploit-db.com/exploits/48263

This exploit demonstrates a directory traversal vulnerability in Joomla! com_fabrik 3.9.11, allowing unauthorized access to files outside the intended directory via crafted HTTP requests. The PoC includes functional curl commands that successfully retrieve file listings from arbitrary directories.

Classification
Working Poc 100%
Attack Type
Info Leak
Complexity
Trivial
Reliability
Reliable
Target: Joomla! com_fabrik 3.9.11
No auth needed
Prerequisites: Joomla! with com_fabrik component installed · Network access to the target
devstral-2 · analyzed May 13, 2026 Full analysis →

References (4)

Core 4
Core References
Exploit exploit
ExploitDB-48263
https://www.exploit-db.com/exploits/48263
Product product
Official Product Homepage
https://fabrikar.com/
Product product
Product Reference
https://fabrikar.com/downloads
Third Party Advisory third-party-advisory
VulnCheck Advisory: Joomla com_fabrik 3.9.11 Directory Traversal via image.php
https://www.vulncheck.com/advisories/joomla-com-fabrik-directory-traversal-via-image-php

Scores

CVSS v3 7.5
EPSS 0.0072
EPSS Percentile 48.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable yes
Technical Impact partial

Details

CWE
CWE-22
Status published
Products (1)
Fabrikar/com_fabrik 3.9.11
Published May 13, 2026
Tracked Since May 13, 2026