In Joomla! 3.2.0 through 3.6.5 (fixed in 3.7.0), inadequate MIME type checks allowed low-privilege users to upload swf files even if they were explicitly forbidden.
{
"versions": [
{
"introduced": "0"
},
{
"last_affected": "3.2.0"
},
{
"introduced": "0"
},
{
"last_affected": "3.2.1"
},
{
"introduced": "0"
},
{
"last_affected": "3.2.2"
},
{
"introduced": "0"
},
{
"last_affected": "3.2.3"
},
{
"introduced": "0"
},
{
"last_affected": "3.2.4"
},
{
"introduced": "0"
},
{
"last_affected": "3.3.0"
},
{
"introduced": "0"
},
{
"last_affected": "3.3.1"
},
{
"introduced": "0"
},
{
"last_affected": "3.3.2"
},
{
"introduced": "0"
},
{
"last_affected": "3.3.3"
},
{
"introduced": "0"
},
{
"last_affected": "3.3.4"
},
{
"introduced": "0"
},
{
"last_affected": "3.3.5"
},
{
"introduced": "0"
},
{
"last_affected": "3.4.0"
},
{
"introduced": "0"
},
{
"last_affected": "3.4.0-alpha"
},
{
"introduced": "0"
},
{
"last_affected": "3.4.0-beta1"
},
{
"introduced": "0"
},
{
"last_affected": "3.4.0-beta2"
},
{
"introduced": "0"
},
{
"last_affected": "3.4.0-beta3"
},
{
"introduced": "0"
},
{
"last_affected": "3.4.1"
},
{
"introduced": "0"
},
{
"last_affected": "3.4.1-rc2"
},
{
"introduced": "0"
},
{
"last_affected": "3.4.2"
},
{
"introduced": "0"
},
{
"last_affected": "3.4.3"
},
{
"introduced": "0"
},
{
"last_affected": "3.4.4"
},
{
"introduced": "0"
},
{
"last_affected": "3.4.5"
},
{
"introduced": "0"
},
{
"last_affected": "3.4.6"
},
{
"introduced": "0"
},
{
"last_affected": "3.4.7"
},
{
"introduced": "0"
},
{
"last_affected": "3.4.8"
},
{
"introduced": "0"
},
{
"last_affected": "3.4.8-rc"
},
{
"introduced": "0"
},
{
"last_affected": "3.5.0"
},
{
"introduced": "0"
},
{
"last_affected": "3.5.0-beta"
},
{
"introduced": "0"
},
{
"last_affected": "3.5.0-beta2"
},
{
"introduced": "0"
},
{
"last_affected": "3.5.0-beta3"
},
{
"introduced": "0"
},
{
"last_affected": "3.5.0-beta4"
},
{
"introduced": "0"
},
{
"last_affected": "3.5.0-beta5"
},
{
"introduced": "0"
},
{
"last_affected": "3.5.0-rc"
},
{
"introduced": "0"
},
{
"last_affected": "3.5.0-rc2"
},
{
"introduced": "0"
},
{
"last_affected": "3.5.0-rc3"
},
{
"introduced": "0"
},
{
"last_affected": "3.5.0-rc4"
},
{
"introduced": "0"
},
{
"last_affected": "3.5.1"
},
{
"introduced": "0"
},
{
"last_affected": "3.5.1-rc"
},
{
"introduced": "0"
},
{
"last_affected": "3.6.0"
},
{
"introduced": "0"
},
{
"last_affected": "3.6.0-alpha"
},
{
"introduced": "0"
},
{
"last_affected": "3.6.0-beta1"
},
{
"introduced": "0"
},
{
"last_affected": "3.6.0-beta2"
},
{
"introduced": "0"
},
{
"last_affected": "3.6.0-rc"
},
{
"introduced": "0"
},
{
"last_affected": "3.6.0-rc2"
},
{
"introduced": "0"
},
{
"last_affected": "3.6.1"
},
{
"introduced": "0"
},
{
"last_affected": "3.6.1-rc1"
},
{
"introduced": "0"
},
{
"last_affected": "3.6.1-rc2"
},
{
"introduced": "0"
},
{
"last_affected": "3.6.2"
},
{
"introduced": "0"
},
{
"last_affected": "3.6.3"
},
{
"introduced": "0"
},
{
"last_affected": "3.6.3-rc1"
},
{
"introduced": "0"
},
{
"last_affected": "3.6.3-rc2"
},
{
"introduced": "0"
},
{
"last_affected": "3.6.3-rc3"
},
{
"introduced": "0"
},
{
"last_affected": "3.6.4"
},
{
"introduced": "0"
},
{
"last_affected": "3.6.5"
}
]
}"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2017-7989.json"
[
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "3.4.0-rc1"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "3.4.1-rc1"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "3.4.2-rc1"
}
]
}
]