Published:2020/04/07  Last Updated:2020/04/07

JVN#56890693
Joomla! plugin "AcyMailing" vulnerable to arbitrary file uploads

Overview

Joomla! plugin "AcyMailing" allows an unauthenticated user to upload arbitrary files (CWE-434).

Products Affected

  • AcyMailing versions prior to 6.9.2

Description

Joomla! plugin "AcyMailing" allows an unauthenticated user to upload arbitrary files (CWE-434).

Impact

Arbitrary PHP code may be executed.

Solution

Update the plugin
Update the plugin according to the information provided by the developer.

Vendor Status

References

JPCERT/CC Addendum

When JPCERT/CC contacted the vendor, AcyMailing version 6.9.2 was already released and CVE-2020-10934 was already assigned.
The vendor states that the vulnerability reported on the report has been fixed on 6.9.2.

Vulnerability Analysis by JPCERT/CC

CVSS v3 CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Base Score: 5.3
Attack Vector(AV) Physical (P) Local (L) Adjacent (A) Network (N)
Attack Complexity(AC) High (H) Low (L)
Privileges Required(PR) High (H) Low (L) None (N)
User Interaction(UI) Required (R) None (N)
Scope(S) Unchanged (U) Changed (C)
Confidentiality Impact(C) None (N) Low (L) High (H)
Integrity Impact(I) None (N) Low (L) High (H)
Availability Impact(A) None (N) Low (L) High (H)
CVSS v2 AV:N/AC:L/Au:N/C:N/I:P/A:N
Base Score: 5.0
Access Vector(AV) Local (L) Adjacent Network (A) Network (N)
Access Complexity(AC) High (H) Medium (M) Low (L)
Authentication(Au) Multiple (M) Single (S) None (N)
Confidentiality Impact(C) None (N) Partial (P) Complete (C)
Integrity Impact(I) None (N) Partial (P) Complete (C)
Availability Impact(A) None (N) Partial (P) Complete (C)

Comment

JPCERT/CC conducted the revalidation of his vulnerability and confirmed that a user without authentication could upload arbitrary files.  Therefore, JPCERT/CC analyzed PR:N and Au:N in CVSS v3.

Credit

qw3rTyTy reported this vulnerability to IPA.
JPCERT/CC coordinated with the developer under Information Security Early Warning Partnership.

Other Information

JPCERT Alert
JPCERT Reports
CERT Advisory
CPNI Advisory
TRnotes
CVE CVE-2020-10934
JVN iPedia JVNDB-2020-000024