A vulnerability has been discovered in older versions of the Joomla! content management software that allow an authenticated attacker to upload active content through the media manager form (‘administrator/components/com_media/helpers/media.php’).
Joomla! allows files with a trailing ‘.’ to pass the upload checks.
Joomla versions 1.6 and greater allow site owners to grant public access to the media manager. For versions 1.5 and greater, the default configuration of Joomla only allows privileged users to access the media manager form. We are not aware if versions earlier than 1.5 are affected.
According to an advisory by the Joomla Security Center, the following versions are affected:
- 2.5.13 and earlier 2.5.x versions
- 3.1.4 and earlier 3.x versions
Solution
Apply an Update
- Update to versions 2.5.14 or 3.1.5 or greater.
In addition, please consider the following workarounds:
Restrict Access
- Apply the appropriate access controls to ensure that only authorized users may access the media manager.