CVE-2025-22213
[20250301] - Core - Malicious file uploads via Media Manager
Inadequate checks in the Media Manager allowed users with "edit" privileges to change file extension to arbitrary extension, including .php and other potentially executable extensions.
CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:L/VI:H/VA:L/SC:L/SI:H/SA:L/AU:N
Affected products
Joomla! Project · Joomla! CMSWant to know if your infrastructure is exposed to this?
Talk to TrueHacking →