EIP-2026-108193
PRE-CVEJoomla! Component ACYMAILING 3.9.0 - Unauthenticated Arbitrary File Upload
Title source: legacyExploitation Summary
EIP tracks 1 public exploit for EIP-2026-108193. PoCs published by qw3rTyTy.
AI-analyzed exploit summary This exploit demonstrates an unauthenticated arbitrary file upload vulnerability in Joomla! ACYMAILING 3.9.0. The vulnerability arises due to lack of CSRF token validation, authentication checks, and file sanitization in the `setNewIconShare()` function, allowing attackers to upload malicious files.
Description
Joomla! Component ACYMAILING 3.9.0 - Unauthenticated Arbitrary File Upload
Exploits (1)
This exploit demonstrates an unauthenticated arbitrary file upload vulnerability in Joomla! ACYMAILING 3.9.0. The vulnerability arises due to lack of CSRF token validation, authentication checks, and file sanitization in the `setNewIconShare()` function, allowing attackers to upload malicious files.