JoomlaÔ¶³Ì´úÂëÖ´ÐÐÎó²î£¨CVE-2021-23132£©
Ðû²¼Ê±¼ä 2021-03-100x00 Îó²î¸ÅÊö
CVE ID | CVE-2021-23132 | ʱ ¼ä | 2021-03-10 |
Àà ÐÍ | RCE | µÈ ¼¶ | ¸ßΣ |
Ô¶³ÌʹÓà | ÊÇ | Ó°Ïì¹æÄ£ | Joomla CMS 3.0.0-3.9.24 |
0x01 Îó²îÏêÇé

JoomlaÊÇÒ»Ì×È«Çò×ÅÃûµÄÄÚÈÝÖÎÀíϵͳ£¬£¬£¬£¬ÆäʹÓÃPHPÓïÑÔºÍ MySQLÊý¾Ý¿â¿ª·¢£¬£¬£¬£¬¿ÉÒÔÔÚLinux¡¢ Windows¡¢MacOSXµÈÖݪֲî±ðµÄƽ̨ÉÏÔËÐС£¡£¡£¡£¡£
2021Äê03ÔÂ06ÈÕ£¬£¬£¬£¬Joomla¹Ù·½Ðû²¼Ç徲ͨ¸æ£¬£¬£¬£¬ÐÞ¸´ÁËJoomlaÖеÄÒ»¸öÔ¶³Ì´úÂëÖ´ÐÐÎó²î£¨CVE-2021-23132£©£¬£¬£¬£¬ÆäCVSSv3ÆÀ·ÖΪ7.5¡£¡£¡£¡£¡£ÓÉÓÚJoomla com_mediaÄ£¿£¿£¿é¶ÔÉÏ´«ÎļþУÑé²»ÑϿᣬ£¬£¬£¬¹¥»÷Õß¿ÉÒÔͨ¹ýÉÏ´«¶ñÒâÎļþ£¬£¬£¬£¬´Ó¶øÊµÏÖÔ¶³Ì´úÂëÖ´ÐС£¡£¡£¡£¡£
×èÖ¹ÏÖÔÚ£¬£¬£¬£¬Í¨¹ýZoomEyeËÑË÷£¬£¬£¬£¬È«Çò¹²630034¸ö̻¶ÔÚ»¥ÁªÍøÉϵÄÍøÕ¾ÕýÔÚʹÓÃJoomla£¬£¬£¬£¬ÆäÖÐÖйúÅÅÃûµÚ7룬£¬£¬£¬¹²¼Æ45045¡£¡£¡£¡£¡£


0x02 ´¦Öóͷ£½¨Òé
ÏÖÔÚ¹Ù·½ÒÑÐÞ¸´ÁË´ËÎó²î£¬£¬£¬£¬½¨ÒéÉý¼¶ÖÁ3.9.25¡£¡£¡£¡£¡£
ÏÂÔØÁ´½Ó£º
https://downloads.joomla.org/cms/joomla3/3-9-25/Joomla_3-9-25-Stable-Full_Package.zip?format=zip
0x03 ²Î¿¼Á´½Ó
https://developer.joomla.org/security-centre/846-20210306-core-com-media-allowed-paths-that-are-not-intended-for-image-uploads.html
https://vti.huaun.com/watchVul?warnId=20888b7e00494e40a350330b0e848d43
https://nvd.nist.gov/vuln/detail/CVE-2021-23132
0x04 ʱ¼äÏß
2021-03-06 JoomlaÐû²¼Ç徲ͨ¸æ
2021-03-10 VSRCÐû²¼Ç徲ͨ¸æ
0x05 ¸½Â¼
CVSSÆÀ·Ö±ê×¼¹ÙÍø£ºhttp://www.first.org/cvss/



¾©¹«Íø°²±¸11010802024551ºÅ