peter bassill · operator
$ cve CVE-2013-5576 JSON

CVE-2013-5576 EXPLOIT

6.8
MEDIUM · CVSS 2.0 · EPSS 48.2% (pctl 99)

Patch early

A public exploit exists.

Description

administrator/components/com_media/helpers/media.php in the media manager in Joomla! 2.5.x before 2.5.14 and 3.x before 3.1.5 allows remote authenticated users or remote attackers to bypass intended access restrictions and upload files with dangerous extensions via a filename with a trailing . (dot), as exploited in the wild in August 2013.

Scoring

CVSS6.8 (MEDIUM, v2.0)
VectorAV:N/AC:M/Au:N/C:P/I:P/A:P
EPSS48.19% — more likely to be exploited than 99% of all CVEs
WeaknessCWE-20
On CISA KEVno
Public exploityes
Published2013-10-09
Last modified2026-06-16

Affected (1)

VendorProduct
joomlajoomla\!

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD