7.5
CVSSv3

CVE-2017-9030

Published: 17/05/2017 Updated: 26/05/2017
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
CVSS v3 Base Score: 7.5 | Impact Score: 3.6 | Exploitability Score: 3.9
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

The Codextrous B2J Contact (aka b2j_contact) extension prior to 2.1.13 for Joomla! allows a directory traversal attack that bypasses a uniqid protection mechanism, and makes it easier to read arbitrary uploaded files.

Vulnerable Product Search on Vulmon Subscribe to Product

codextrous b2j contact

Exploits

Joomla Codextrous B2jcontact component version 2117 suffers from a remote shell upload vulnerability ...