The Joomla file cache storage handler appended the cache group name to the cache root without rejecting '..' segments, so the containment check in FileStorage::_deleteFolder() could be bypassed. An administrator-area user with access to Cache Management (com_cache) could submit a crafted group such as ../../images to the cache clean action and... Weiterlesen: Arbitrary Directory Deletion via Path Traversal in Joomla Cache File …
Intelligence View
⚡ tsecurity.de Intelligence
Arbitrary Directory Deletion via Path Traversal in Joomla Cache File Storage
The Joomla file cache storage handler appended the cache group name to the cache root without rejecting '..' segments, so the containment check in…
Cyber Threat Intelligence & Forensik
ATT&CK-Navigator · IoC-Radar · Exploit-Belege