"value":"AnyMailing Joomla Plugin is vulnerable to unauthenticated remote code execution, when being granted access to the campaign's creation on front-office due to unrestricted file upload allowing PHP code to be injected. This issue affects AnyMailing Joomla Plugin Enterprise in versions below 8.3.0."
}
]
},
"problemtype":{
"problemtype_data":[
{
"description":[
{
"lang":"eng",
"value":"CWE-20 Improper Input Validation",
"cweId":"CWE-20"
}
]
},
{
"description":[
{
"lang":"eng",
"value":"CWE-434 Unrestricted Upload of File with Dangerous Type",
"cweId":"CWE-434"
}
]
}
]
},
"affects":{
"vendor":{
"vendor_data":[
{
"vendor_name":"AcyMailing",
"product":{
"product_data":[
{
"product_name":"Newsletter Plugin for Joomla in the Enterprise version",