Several Joomla core forms validated URL fields without restricting the allowed schemes, so the News Feeds link, the Feed Display module, the Scheduled Tasks GET request and the Joomla Update custom source accepted file://, gopher://, ldap:// and similar URLs. A manager-level user, or a user who can create modules or scheduled tasks, could make the... Weiterlesen: Server-Side Request Forgery in Joomla Core URL Fields
Intelligence View
⚡ tsecurity.de Intelligence
Server-Side Request Forgery in Joomla Core URL Fields
Several Joomla core forms validated URL fields without restricting the allowed schemes, so the News Feeds link, the Feed Display module, the Scheduled Tasks…
Cyber Threat Intelligence & Forensik
ATT&CK-Navigator · IoC-Radar · Exploit-Belege