CVE-2020-23972 EXPLOIT
7.5
HIGH · CVSS 3.1 · EPSS 31.4% (pctl 98)
Patch early
A public exploit exists.
Description
In Joomla Component GMapFP Version J3.5 and J3.5free, an attacker can access the upload function without authenticating to the application and can also upload files which due to issues of unrestricted file uploads which can be bypassed by changing the content-type and name file too double extensions.
Scoring
| CVSS | 7.5 (HIGH, v3.1) |
|---|---|
| Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N |
| EPSS | 31.44% — more likely to be exploited than 98% of all CVEs |
| Weakness | CWE-434 |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2020-08-27 |
| Last modified | 2026-06-17 |
Affected (1)
| Vendor | Product |
|---|---|
| gmapfp | gmapfp |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | Joomla! Component GMapFP 3.5 - Unauthenticated Arbitrary File Upload | 2020-12-01 |
References
- http://packetstormsecurity.com/files/159072/Joomla-GMapFP-J3.5-J3.5F-Arbitrary-File-Upload.html
- https://raw.githubusercontent.com/me4yoursecurity/Reports/master/README.md
- http://packetstormsecurity.com/files/159072/Joomla-GMapFP-J3.5-J3.5F-Arbitrary-File-Upload.html
- https://raw.githubusercontent.com/me4yoursecurity/Reports/master/README.md
→ the Explorer · watch your stack · NVD