Skip to content

Path Disclosure within joomla/filesystem class

Moderate severity GitHub Reviewed Published Mar 31, 2022 to the GitHub Advisory Database • Updated May 15, 2024

Package

composer joomla/filesystem (Composer)

Affected versions

< 1.6.2
>= 2.0.0, < 2.0.1

Patched versions

1.6.2
2.0.1

Description

An issue was discovered in Joomla! 3.0.0 through 3.10.6 & 4.0.0 through 4.1.0. Uploading a file name of an excess length causes the error. This error brings up the screen with the path of the source code of the web application.

References

Published by the National Vulnerability Database Mar 30, 2022
Published to the GitHub Advisory Database Mar 31, 2022
Last updated May 15, 2024
Reviewed May 15, 2024

Severity

Moderate
5.3
/ 10

CVSS base metrics

Attack vector
Network
Attack complexity
Low
Privileges required
None
User interaction
None
Scope
Unchanged
Confidentiality
Low
Integrity
None
Availability
None
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

Weaknesses

CVE ID

CVE-2022-23794

GHSA ID

GHSA-rc8q-45v8-x6xc
Checking history
See something to contribute? Suggest improvements for this vulnerability.