CVE-2021-28377
Joomla! ChronoForums 2.0.11 - Local File Inclusion
Record summary
CVE-2021-28377 has a selected CVSS score of 5.3 (medium); EIP currently links 1 Nuclei template.
Description
ChronoForums 2.0.11 allows av Directory Traversal to read arbitrary files.
Exploitation context
Available material
- Nuclei templates
- 1
Nuclei templates
1ProjectDiscoveryMEDIUMJoomla! ChronoForums 2.0.11 - Local File InclusionCVSS 5.3
Joomla! ChronoForums 2.0.11 avatar function is vulnerable to local file inclusion through unauthenticated path traversal attacks. This enables an attacker to read arbitrary files, for example the Joomla! configuration file which contains credentials.
Impact
The LFI vulnerability can lead to unauthorized access to sensitive files, potentially exposing sensitive information or allowing remote code execution.
Remediation
Update Joomla! ChronoForums to the latest version (2.0.12) or apply the provided patch to fix the LFI vulnerability.
Source: ProjectDiscovery