Description
A remote file inclusion vulnerability was reported in Joomla! core. It is possible for a remote attacker to extract a remotely hosted archive while you are extracting a backup archive or installing an update, depending on your server settings.
Affected versions:
Versions: 2.5.4 through 2.5.25, 3.2.5 and earlier 3.x versions, 3.3.0 through 3.3.4.
Remediation
Upgrade to the latest version of Joomla!.
References
Related Vulnerabilities
WordPress Plugin Mailing List 'wpabspath' Parameter Remote File Include (1.3.3)
vBulletin routestring Local File Inclusion
ZK Framework AuUploader Information Disclosure (CVE-2022-36537)
WordPress Plugin kk Star Ratings 'root' Parameter Remote File Include (1.7)
WordPress Plugin Photo Gallery by 10Web-Mobile-Friendly Image Gallery Local File Inclusion (1.5.24)