Description
An issue was discovered in Joomla! 3.0.0 through 3.10.6 & 4.0.0 through 4.1.0. Extracting an specifilcy crafted tar package could write files outside of the intended path.
Remediation
References
Related Vulnerabilities
WordPress Plugin Product Catalog SQL Injection (4.2.2)
Drupal Cryptographic Issues Vulnerability (CVE-2013-6386)
WordPress Plugin Lightbox Multiple Unspecified Vulnerabilities (2.0.7)
WordPress Plugin WP Courses LMS Cross-Site Scripting (2.0.43)
WordPress Plugin WooCommerce Smart Coupons Security Bypass (4.6.0)