Joomla! Object Injection Vulnerability
Critical severity
GitHub Reviewed
Published
May 13, 2022
to the GitHub Advisory Database
•
Updated Sep 28, 2023
Description
Published by the National Vulnerability Database
Feb 12, 2019
Published to the GitHub Advisory Database
May 13, 2022
Reviewed
Jul 19, 2023
Last updated
Sep 28, 2023
An issue was discovered in Joomla! before 3.9.3. The phar:// stream wrapper can be used for object injection attacks because there is no protection mechanism (such as the TYPO3 PHAR stream wrapper) to prevent use of the phar:// handler for non .phar-files.
References