Tiny browser included with TinyMCE 3.0 editor allowed files to be uploaded and removed without logging in.
Part of security release: 1.5.12
This vulnerability affects the following application versions:
- Joomla 1.5.0
- Joomla 1.5.1
- Joomla 1.5.2
- Joomla 1.5.3
- Joomla 1.5.4
- Joomla 1.5.5
- Joomla 1.5.6
- Joomla 1.5.7
- Joomla 1.5.8
- Joomla 1.5.9
- Joomla 1.5.10
- Joomla 1.5.11
- Joomla 1.5.12