CVE-2026-76597
8.7
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N
Summary
Joomla Extension - fabrikar.com - Unauthenticated arbitrary file upload to web root via list email plugin in Fabrik < 4.7.2 - The list email plugin controller allows to upload non-executable files to the webroot.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| fabrikar.com | Fabrik extension for Joomla | 1.0.0-4.7.1 | affected |
Weaknesses
- CWE-284: CWE-284 Improper Access Control
References
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.