Harmistechnology

Je Messenger

5 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.23%
  • Veröffentlicht 29.03.2019 15:29:00
  • Zuletzt bearbeitet 21.11.2024 04:52:34

An issue was discovered in the Harmis JE Messenger component 1.2.2 for Joomla!. Input does not get validated and queries are not written in a way to prevent SQL injection. Therefore arbitrary SQL-Statements can be executed in the database.

  • EPSS 0.21%
  • Veröffentlicht 29.03.2019 15:29:00
  • Zuletzt bearbeitet 21.11.2024 04:52:34

An issue was discovered in the Harmis JE Messenger component 1.2.2 for Joomla!. It is possible to craft messages in a way that JavaScript gets executed on the side of the receiving user when the message is opened, aka XSS.

  • EPSS 0.3%
  • Veröffentlicht 29.03.2019 15:29:00
  • Zuletzt bearbeitet 21.11.2024 04:52:34

An issue was discovered in the Harmis JE Messenger component 1.2.2 for Joomla!. It is possible to perform an action within the context of the account of another user.

  • EPSS 0.21%
  • Veröffentlicht 29.03.2019 15:29:00
  • Zuletzt bearbeitet 21.11.2024 04:52:34

An issue was discovered in the Harmis JE Messenger component 1.2.2 for Joomla!. It is possible to read information that should only be accessible by a different user.

  • EPSS 85.22%
  • Veröffentlicht 29.03.2019 15:29:00
  • Zuletzt bearbeitet 21.11.2024 04:52:34

An issue was discovered in the Harmis JE Messenger component 1.2.2 for Joomla!. Directory Traversal allows read access to arbitrary files.