8.7
CVE-2019-25762
- EPSS 0.54%
- Veröffentlicht 19.06.2026 17:48:44
- Zuletzt bearbeitet 21.08.2026 14:40:10
- CVE-Watchlists
- Unerledigt
Joomla! Component JoomProject 1.1.3.2 Information Disclosure
Joomla! Component JoomProject 1.1.3.2 contains an information disclosure vulnerability that allows unauthenticated attackers to access sensitive user data by exploiting the projects endpoint. Attackers can send requests to index.php with option=com_jpprojects&view=projects&tmpl=component&format=json parameters to retrieve user IDs, names, and email addresses in JSON format.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Joomboost ≫ Joomproject Version1.1.3.2 SwPlatformjoomla!
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.54% | 0.422 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| disclosure@vulncheck.com | 8.7 | 0 | 0 |
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
|
| disclosure@vulncheck.com | 7.5 | 3.9 | 3.6 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
|
CWE-359 Exposure of Private Personal Information to an Unauthorized Actor
The product does not properly prevent a person's private, personal information from being accessed by actors who either (1) are not explicitly authorized to access the information or (2) do not have the implicit consent of the person about whom the information is collected.
http://joomboost.com/
https://www.exploit-db.com/exploits/46121
https://extensions.joomla.org/extensions/extension/clients-a-communities/project-a-task-management/joomproject/
https://www.vulncheck.com/advisories/joomla-component-joomproject-information-disclosure