PoC Index

CVE-2020-23972

HIGH 7.5EPSS 31.4%

In Joomla Component GMapFP Version J3.5 and J3.5free, an attacker can access the upload function without authenticating to the application and can also upload files which due to issues of unrestricted file uploads which can be bypassed by changing the content-type and name file too double extensions.

CVSS v3.1
7.5 HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
CVSS v2.0
5.0 MEDIUMAV:N/AC:L/Au:N/C:N/I:P/A:N
EPSS
31.44% chance of exploitation in the next 30 days, 98th percentile
Nuclei
high · CWE-434
Published
2020-08-27
Updated
2024-08-04

Proof-of-concept exploits (1)

Nuclei templates (1)

ExploitDB entries (1)

References

Related