Critical severity9.8NVD Advisory· Published Mar 30, 2023· Updated Jun 17, 2026
CVE-2023-28731
CVE-2023-28731
Description
AnyMailing Joomla Plugin is vulnerable to unauthenticated remote code execution, when being granted access to the campaign's creation on front-office due to unrestricted file upload allowing PHP code to be injected.
This issue affects AnyMailing Joomla Plugin Enterprise in versions below 8.3.0.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
4- Range: <8.3.0
- Range: <8.3.0
- AcyMailing/Newsletter Plugin for Joomla in the Enterprise versionv5Range: 0
Patches
Vulnerability mechanics
References
2- www.bugbounty.ch/advisories/CVE-2023-28731nvdExploitThird Party Advisory
- www.acymailing.com/change-log/nvdRelease Notes
News mentions
0No linked articles in our index yet.