GHSA-f3gp-9xr4-qmvcHighCVSS 7.6
Joomla 6.1.1 contains a path traversal vulnerability in the com_joomlaupdate extension that...
🔗 CVE IDs covered (1)
📋 Description
Joomla 6.1.1 contains a path traversal vulnerability in the com_joomlaupdate extension that allows a Super User to be induced into extracting a crafted archive containing directory traversal sequences or absolute paths in ZIP entry filenames. Attackers can supply malicious ZIP entry names with parent-directory segments or absolute paths to the extract.php extraction routine, causing files to be written outside the intended destination root and enabling persistent remote code execution via planted PHP files.
🔗 References (6)
- https://nvd.nist.gov/vuln/detail/CVE-2026-73327
- https://github.com/joomla/joomla-cms/pull/48057
- https://github.com/joomla/joomla-cms/commit/9678a171d37e1e10ca75c9124bdafe20fe14fa5b
- https://github.com/joomla/joomla-cms
- https://www.vulncheck.com/advisories/joomla-zip-slip-path-traversal-via-com-joomlaupdate-extract-php
- https://github.com/advisories/GHSA-f3gp-9xr4-qmvc