7.5
CVSSv3

CVE-2017-5214

Published: 17/05/2017 Updated: 03/10/2019
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
CVSS v3 Base Score: 7.5 | Impact Score: 3.6 | Exploitability Score: 3.9
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

The Codextrous B2J Contact (aka b2j_contact) extension prior to 2.1.13 for Joomla! allows prediction of a uniqid value based on knowledge of a time value. This makes it easier to read arbitrary uploaded files.

Vulnerable Product Search on Vulmon Subscribe to Product

codextrous b2j contact

Exploits

Joomla Codextrous B2jcontact component version 2117 suffers from a remote shell upload vulnerability ...