CVE-2021-23132
HIGHJoomla! 3.0.0-3.9.24 - Unauthenticated Arbitrary File Upload via com_media
Title source: llmExploitation Summary
EIP tracks 2 public exploits for CVE-2021-23132. PoCs published by HoangKien1020, securitystuffbackup.
AI-analyzed exploit summary The repository contains a functional Python exploit for CVE-2021-23132, which leverages a path traversal vulnerability in Joomla's com_media component to achieve remote code execution (RCE). The exploit requires admin credentials and demonstrates the ability to create a superadmin account and execute arbitrary commands.
Description
An issue was discovered in Joomla! 3.0.0 through 3.9.24. com_media allowed paths that are not intended for image uploads
Exploits (2)
The repository contains a functional Python exploit for CVE-2021-23132, which leverages a path traversal vulnerability in Joomla's com_media component to achieve remote code execution (RCE). The exploit requires admin credentials and demonstrates the ability to create a superadmin account and execute arbitrary commands.
The repository contains a functional Python exploit for CVE-2021-23132, which leverages a path traversal vulnerability in Joomla's com_media component to achieve remote code execution (RCE). The exploit requires admin credentials and demonstrates the ability to create a superadmin account and execute arbitrary commands.
References (1)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N