QID 730634
Date Published: 2022-11-09
QID 730634: Joomla Multiple Full Path Disclosure Vulnerability (20220801)
Joomla is a free and open-source content management system written in PHP. It uses object oriented programming techniques and is built on a model-view-controller web application framework. It includes features such as page caching, RSS feeds, printable versions of pages, news flashes, blogs, polls, search, and support for language internationalization.
CVE-2022-27911: Multiple Full Path Disclosures because of missing '_JEXEC or die check' caused by the PSR12 changes done in 4.2.0.
Affected Version:
Joomla! CMS version 4.2.0
Fixed Version:
Upgrade to version 4.2.1
QID Detection Logic(Unauthenticated):
QID checks for the Vulnerable version of Joomla.
Successful exploitation of this vulnerability may allow an remote attacker to gain access to potentially sensitive information.
- 20220801 -
developer.joomla.org/security-centre.html
CVEs related to QID 730634
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| 20220801 |
|