CVE-2011-5004: Fabrikar Com Fabrikar
Medium severity, CVSS 6.0. EPSS: 1.7% chance of exploitation in the next 30 days.
Unrestricted file upload vulnerability in models/importcsv.php in the Fabrik (com_fabrik) component before 2.1.1 for Joomla! allows remote authenticated users with Manager privileges to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in an unspecified directory.
Affected products
- Fabrikar Com Fabrikar: up to and including 2.1; version 1.0.1 only; version 1.0.6 only; version 2.0.2 only; version 2.0.4 only; version 2.0.5 only
Published 2011-12-25. Last modified 2026-06-16.