CVE-2022-23794Information Exposure via Error Message in Joomla Filesystem

Severity
5.3MEDIUMNVD
EPSS
0.0%
top 99.40%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMar 30
Latest updateMar 31

Description

An issue was discovered in Joomla! 3.0.0 through 3.10.6 & 4.0.0 through 4.1.0. Uploading a file name of an excess length causes the error. This error brings up the screen with the path of the source code of the web application.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:NExploitability: 3.9 | Impact: 1.4

Affected Packages4 packages

CVEListV5joomla!_project/joomla_filesystem1.0.0-1.6.1 & 2.0.0
Packagistjoomla/filesystem2.0.02.0.1+1
NVDjoomla/joomla_!3.0.03.10.6+1
CVEListV5joomla!_project/joomla!_cms3.0.0-3.10.6 & 4.0.0-4.1.0

🔴Vulnerability Details

3
GHSA
Path Disclosure within joomla/filesystem class2022-03-31
OSV
Path Disclosure within joomla/filesystem class2022-03-31
CVEList
[20220302] - Core - Path Disclosure within filesystem error messages2022-03-30
CVE-2022-23794 — Information Exposure via Error Message | cvebase