VULNERABILITY INTELLIGENCE

CVE-2015-8564

CVSS score7.5 HIGH
EPSS probability2.64%
CISA KEVNot currently listed
Published2015-12-16
Last modified2026-06-17
CVSS vectorAV:N/AC:L/Au:N/C:P/I:P/A:P

Description

Directory traversal vulnerability in Joomla! 3.4.x before 3.4.6 allows remote attackers to have unspecified impact via directory traversal sequences in the XML install file in an extension package archive.

Weakness classification

  • CWE-20: Improper Input Validation
  • CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

Primary references