LIVE · cybersecurity feed
Live wire
cve recordhigh

CVE-2019-25762

joomboost · joomproject

Published
CVSS7.5
Severityhigh
WeaknessCWE-359
ExploitedNot in CISA KEV

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Description

Joomla! Component JoomProject 1.1.3.2 contains an information disclosure vulnerability that allows unauthenticated attackers to access sensitive user data by exploiting the projects endpoint. Attackers can send requests to index.php with option=com_jpprojects&view=projects&tmpl=component&format=json parameters to retrieve user IDs, names, and email addresses in JSON format.

References

← Back to the CVE Tracker

Our coverage of CVE-2019-25762

No stories yet. This page updates automatically when we publish reporting that references CVE-2019-25762.