VULNERABILITY INTELLIGENCE
CVE-2015-8564
CVSS score7.5 HIGH
EPSS probability2.64%
CISA KEVNot currently listed
Published2015-12-16
Last modified2026-06-17
CVSS vectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Description
Directory traversal vulnerability in Joomla! 3.4.x before 3.4.6 allows remote attackers to have unspecified impact via directory traversal sequences in the XML install file in an extension package archive.
Weakness classification
- CWE-20: Improper Input Validation
- CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
Primary references
- cve@mitre.org — Vendor Advisory
- af854a3a-2127-422b-91ae-364da2661108 — Vendor Advisory