CVE-2023-28731
CVE-2023-28731
9.8
CriticalPublished:
Last updated:
Source:vulnerability@ncsc.ch
Modified
CVSS Vector
v3.1- Attack Vector
- Network
- Attack Complexity
- Low
- Privileges Required
- None
- User Interaction
- None
- Scope
- Unchanged
- Confidentiality
- High
- Integrity
- High
- Availability
- High
Description
AnyMailing Joomla Plugin is vulnerable to unauthenticated remote code execution, when being granted access to the campaign's creation on front-office due to unrestricted file upload allowing PHP code to be injected. This issue affects AnyMailing Joomla Plugin Enterprise in versions below 8.3.0.
References
vulnerability@ncsc.ch
https://www.acymailing.com/change-log/vulnerability@ncsc.ch
https://www.bugbounty.ch/advisories/CVE-2023-28731af854a3a-2127-422b-91ae-364da2661108
https://www.acymailing.com/change-log/af854a3a-2127-422b-91ae-364da2661108
https://www.bugbounty.ch/advisories/CVE-2023-28731