Vulnerability Description
Joomla! Component JoomProject 1.1.3.2 contains an information disclosure vulnerability that allows unauthenticated attackers to access sensitive user data by exploiting the projects endpoint. Attackers can send requests to index.php with option=com_jpprojects&view=projects&tmpl=component&format=json parameters to retrieve user IDs, names, and email addresses in JSON format.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Joomboost | Joomproject | 1.1.3.2 |
Related Weaknesses (CWE)
References
- http://joomboost.com/Product
- https://extensions.joomla.org/extensions/extension/clients-a-communities/projectProduct
- https://www.exploit-db.com/exploits/46121ExploitVDB Entry
- https://www.vulncheck.com/advisories/joomla-component-joomproject-information-diThird Party Advisory
FAQ
What is CVE-2019-25762?
CVE-2019-25762 is a vulnerability with a CVSS score of 7.5 (HIGH). Joomla! Component JoomProject 1.1.3.2 contains an information disclosure vulnerability that allows unauthenticated attackers to access sensitive user data by exploiting the projects endpoint. Attacker...
How severe is CVE-2019-25762?
CVE-2019-25762 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2019-25762?
Check the references section above for vendor advisories and patch information. Affected products include: Joomboost Joomproject.