New Joomla! Novarain/Tassos Framework Vulnerabilities Advisory

News

Source code review of the Novarain/Tassos framework uncovered 3 critical primitives: unauthenticated file read, unauthenticated file deletion, and SQL injection enabling arbitrary DB reads, affecting 5 widely deployed Joomla! Extensions. Chained together, these bugs allow reliable RCE and administrator account takeover on unpatched Joomla! Instances. submitted by /u/SSDisclosure [link] [comments]Technical Information Security Content & DiscussionRead More