CVE-2023-28732

Vulnérabilités

CVE-2023-28732

Missing access control in AnyMailing Joomla Plugin allows to list and access files containing sensitive information from the plugin itself and access to system…

HIGH acymailing

Missing access control in AnyMailing Joomla Plugin allows to list and access files containing sensitive information from the plugin itself and access to system files via path traversal, when being granted access to the campaign's creation on front-office. This issue affects AnyMailing Joomla Plugin in versions below 8.3.0.

7.5 Élevée · CVSS 3.1

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Score retenu : NVD

SourceSévérité d'origineCVSS
NVDHIGH 7.5 (v3.1)
Produit
acymailing
Corrigée dans
8.3.0
Publiée
30/03/2023
Modifiée
17/06/2026
CWE
CWE-20, CWE-200, CWE-22
  • Newsletter Plugin for Joomla — 0 – 0
  • acymailing — jusqu'à 8.3.0 (exclue)

Ces informations proviennent des sources ci-dessus ; CVE Oyer n'y ajoute aucune interprétation.

  1. Détectée via nvd26/09/2026 09:34 UTC