Vulnerability Description
In Joomla component 'jDownloads 3.9.8.2 Stable' the remote user can change some parameters in the address bar and see the names of other users' files
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Jdownloads | Jdownloads | 3.9.8.2 |
References
- https://hackerhood.redhotcyber.com/cve-2022-27909-jdownloads/Third Party Advisory
- https://www.jdownloads.com/index.php/downloads/download/57-jdownloads-3-9.htmlRelease NotesVendor Advisory
- https://hackerhood.redhotcyber.com/cve-2022-27909-jdownloads/Third Party Advisory
- https://www.jdownloads.com/index.php/downloads/download/57-jdownloads-3-9.htmlRelease NotesVendor Advisory
FAQ
What is CVE-2022-27909?
CVE-2022-27909 is a vulnerability with a CVSS score of 4.3 (MEDIUM). In Joomla component 'jDownloads 3.9.8.2 Stable' the remote user can change some parameters in the address bar and see the names of other users' files
How severe is CVE-2022-27909?
CVE-2022-27909 has been rated MEDIUM with a CVSS base score of 4.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2022-27909?
Check the references section above for vendor advisories and patch information. Affected products include: Jdownloads Jdownloads.