CVE-2023-28731

CVSS V2 None CVSS V3 None
Description
AnyMailing Joomla Plugin is vulnerable to unauthenticated remote code execution, when being granted access to the campaign's creation on front-office due to unrestricted file upload allowing PHP code to be injected. This issue affects AnyMailing Joomla Plugin Enterprise in versions below 8.3.0.
Overview
  • CVE ID
  • CVE-2023-28731
  • Assigner
  • vulnerability@ncsc.ch
  • Vulnerability Status
  • Analyzed
  • Published Version
  • 2023-03-30T12:15:07
  • Last Modified Date
  • 2023-04-06T17:28:23
CPE Configuration (Product)
CPE Vulnerable Operator Version Start Version End
cpe:2.3:a:acymailing:acymailing:*:*:*:*:*:joomla\!:*:* 1 OR 8.3.0
References
Reference URL Reference Tags
https://www.acymailing.com/change-log/ Release Notes
https://www.bugbounty.ch/advisories/CVE-2023-28731 Exploit Third Party Advisory
History
Created Old Value New Value Data Type Notes
2023-04-17 03:54:51 Added to TrackCVE
2023-04-17 03:54:54 Weakness Enumeration new