An issue was discovered in Joomla! before 3.8.13. com_joomlaupdate allows the execution of arbitrary code. The default ACL config enabled the ability of Administrator-level users to access com_joomlaupdate and trigger code execution.
| Package (Ecosystem) | Introduced | Fixed | Limit |
|---|---|---|---|
| joomla/framework(Packagist) | 2.5.4 | 3.8.13 | N/A |
CVSS Metrics