CVE-2018-17856: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
(updated )
An issue was discovered in Joomla! before 3.8.13. com_joomlaupdate allows the execution of arbitrary code. The default ACL config enabled the ability of Administrator-level users to access com_joomlaupdate and trigger code execution.
References
- developer.joomla.org/security-centre/752-20181002-core-inadequate-default-access-level-for-com-joomlaupdate.html
- github.com/advisories/GHSA-9m72-pw47-292w
- nvd.nist.gov/vuln/detail/CVE-2018-17856
- web.archive.org/web/20210124211736/http://www.securityfocus.com/bid/105559
- web.archive.org/web/20211208125303/http://www.securitytracker.com/id/1041914
Detect and mitigate CVE-2018-17856 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →