Description
An issue was discovered in Joomla! 2.5.0 through 3.8.8 before 3.8.9. The autoload code checks classnames to be valid, using the "class_exists" function in PHP. In PHP 5.3, this function validates invalid names as valid, which can result in a Local File Inclusion.
Remediation
References
Related Vulnerabilities
WordPress Plugin BuddyPress Security Bypass (5.1.0)
MySQL CVE-2013-3806 Vulnerability (CVE-2013-3806)
WordPress Plugin Import any XML or CSV File to WordPress Cross-Site Scripting (3.4.6)
WordPress Plugin ActiveCampaign-Forms, Site Tracking, Live Chat Unspecified Vulnerability (5.7)
OpenSSL Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2016-2178)