QID 154125

Date Published: 2022-10-31

QID 154125: Joomla! Core: Debug Mode Information Disclosure Vulnerability (CVE-2022-27912)

Joomla! is a free and open-source content management system for publishing web content on websites.

An issue was discovered in Joomla. Sites with publicly enabled debug mode exposed data of previous requests..

Affected Versions:
Joomla! CMS versions 4.0.0 to 4.2.3

QID Detection Logic:(Unauthenticated)
This QID checks for vulnerable version of Joomla installed on the target.

Successful exploitation of this vulnerability could reveal sensitive information to an unauthorized attacker.

  • CVSS V3 rated as Medium - 5.3 severity.
  • CVSS V2 rated as Medium - 5 severity.
  • Solution
    Customers are advised to install latest Joomla version.
    For more information visit Joomla security advisory [20221001].

    CVEs related to QID 154125

    Software Advisories
    Advisory ID Software Component Link
    20221001 URL Logo developer.joomla.org/security-centre/885-20221001-core-disclosure-of-critical-information-in-debug-mode.html