CVE-2019-14654
Summary
| CVE | CVE-2019-14654 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2019-08-05 01:15:00 UTC |
| Updated | 2020-08-24 17:37:00 UTC |
| Description | In Joomla! 3.9.7 and 3.9.8, inadequate filtering allows users authorised to create custom fields to manipulate the filtering options and inject an unvalidated option. In other words, the filter attribute in subform fields allows remote code execution. This is fixed in 3.9.9. |
Risk And Classification
Problem Types: NVD-CWE-noinfo
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Joomla | Joomla! | 3.9.7 | - | All | All |
| Application | Joomla | Joomla! | 3.9.7 | rc | All | All |
| Application | Joomla | Joomla! | 3.9.8 | All | All | All |
| Application | Joomla | Joomla! | 3.9.7 | - | All | All |
| Application | Joomla | Joomla! | 3.9.7 | rc | All | All |
| Application | Joomla | Joomla! | 3.9.8 | All | All | All |
| Application | Joomla | Joomla! | 3.9.7 | - | All | All |
| Application | Joomla | Joomla! | 3.9.7 | rc | All | All |
| Application | Joomla | Joomla! | 3.9.8 | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| [20190701] - Core - Filter attribute in subform fields allows remote code execution | MISC | developer.joomla.org | Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.