GHSA-f3gp-9xr4-qmvcHighCVSS 7.6

Joomla 6.1.1 contains a path traversal vulnerability in the com_joomlaupdate extension that...

Published
August 12, 2026
Last Modified
August 12, 2026

🔗 CVE IDs covered (1)

📋 Description

Joomla 6.1.1 contains a path traversal vulnerability in the com_joomlaupdate extension that allows a Super User to be induced into extracting a crafted archive containing directory traversal sequences or absolute paths in ZIP entry filenames. Attackers can supply malicious ZIP entry names with parent-directory segments or absolute paths to the extract.php extraction routine, causing files to be written outside the intended destination root and enabling persistent remote code execution via planted PHP files.

🔗 References (6)