Description
An issue was discovered in Joomla! 3.0.0 through 3.10.6 & 4.0.0 through 4.1.0. Extracting an specifilcy crafted tar package could write files outside of the intended path.
Remediation
References
Related Vulnerabilities
Oracle JRE CVE-2013-2464 Vulnerability (CVE-2013-2464)
PHP Improper Input Validation Vulnerability (CVE-2016-4537)
WordPress Plugin Multisite Global Search 'mssearch' Parameter Cross-Site Scripting (1.2.5)
WordPress Plugin AI ChatBot SQL Injection (4.8.9)
Drupal Improper Input Validation Vulnerability (CVE-2022-25273)