CVE-2019-9918
- EPSS 0.23%
- Veröffentlicht 29.03.2019 15:29:00
- Zuletzt bearbeitet 21.11.2024 04:52:34
An issue was discovered in the Harmis JE Messenger component 1.2.2 for Joomla!. Input does not get validated and queries are not written in a way to prevent SQL injection. Therefore arbitrary SQL-Statements can be executed in the database.
CVE-2019-9919
- EPSS 0.21%
- Veröffentlicht 29.03.2019 15:29:00
- Zuletzt bearbeitet 21.11.2024 04:52:34
An issue was discovered in the Harmis JE Messenger component 1.2.2 for Joomla!. It is possible to craft messages in a way that JavaScript gets executed on the side of the receiving user when the message is opened, aka XSS.
CVE-2019-9920
- EPSS 0.3%
- Veröffentlicht 29.03.2019 15:29:00
- Zuletzt bearbeitet 21.11.2024 04:52:34
An issue was discovered in the Harmis JE Messenger component 1.2.2 for Joomla!. It is possible to perform an action within the context of the account of another user.
CVE-2019-9921
- EPSS 0.21%
- Veröffentlicht 29.03.2019 15:29:00
- Zuletzt bearbeitet 21.11.2024 04:52:34
An issue was discovered in the Harmis JE Messenger component 1.2.2 for Joomla!. It is possible to read information that should only be accessible by a different user.
CVE-2019-9922
- EPSS 85.22%
- Veröffentlicht 29.03.2019 15:29:00
- Zuletzt bearbeitet 21.11.2024 04:52:34
An issue was discovered in the Harmis JE Messenger component 1.2.2 for Joomla!. Directory Traversal allows read access to arbitrary files.