CVE-2015-7341
JNews Joomla Component before 8.5.0 allows arbitrary File Upload via Subscribers or Templates, as demonstrated by the .php5 extension.
HIGH
jnews
Description
JNews Joomla Component before 8.5.0 allows arbitrary File Upload via Subscribers or Templates, as demonstrated by the .php5 extension.
Sévérité
8.8
Élevée · CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Score retenu : NVD
| Source | Sévérité d'origine | CVSS |
|---|---|---|
| NVD | HIGH | 8.8 (v3.1) |
Produit et versions
- Produit
- jnews
- Corrigée dans
- 8.5.0
- Publiée
- 09/03/2020
- Modifiée
- 17/06/2026
- CWE
- CWE-434
Versions concernées
- jnews — jusqu'à 8.5.0 (exclue)
Sources
- NVD CVE-2015-7341 vu
Ces informations proviennent des sources ci-dessus ; CVE Oyer n'y ajoute aucune interprétation.
Historique
- Détectée via nvd26/09/2026 09:34 UTC