Description
An issue was discovered in Joomla! before 3.9.3. The phar:// stream wrapper can be used for objection injection attacks because there is no protection mechanism (such as the TYPO3 PHAR stream wrapper) to prevent use of the phar:// handler for non .phar-files.
Remediation
References
Related Vulnerabilities
WordPress Plugin Joy Of Text Lite-SMS messaging for WordPress SQL Injection (2.3.0)
WordPress Plugin Fancy Gallery Cross-Site Scripting (1.5.12)
WordPress Plugin Mail Masta Local File Inclusion (1.0)
WordPress Other Vulnerability (CVE-2013-0235)
WordPress Plugin WP No External Links Cross-Site Scripting (3.5.15)