Subscribe to Joomla! Security Announcements - Click Here

Wed

22

Jul

2009

[20090722] - Core - File Upload
Wednesday, 22 July 2009 23:17
  • Project: Joomla!
  • SubProject: TinyMCE editor
  • Severity: Critical
  • Versions: 1.5.12
  • Exploit type: Image File upload
  • Reported Date: 2009-July-22
  • Fixed Date: 2009-July-22

Description

Tiny browser included with TinyMCE 3.0 editor allowed files to be uploaded and removed without logging in.

Affected Installs

Version 1.5.12 only

Solution

Upgrade to latest Joomla! version (1.5.13 or newer).

Reported by Patrice Lazareff.

Contact

The JSST at the Joomla! Security Center.

Last Updated on Thursday, 23 July 2009 04:34