A vulnerability in the JCE editor extension for Joomla allows the creation of new editor profiles for unauthenticated users, ultimately resulting in PHP code upload and execution.
Attack Parameters
Impact Assessment
CVSS Vector v4.0
Weakness Type (CWE)
Vulnerable Products 1
| Configuration | From (including) | Up to (excluding) |
|---|---|---|
|
Widgetfactorylimited Jce
cpe:2.3:a:widgetfactorylimited:jce:*:*:*:*:*:joomla\!:*:*
|
— |
2.9.99.5
|