CVE-2022-23799Joomla Input vulnerability

4 documents4 sources
Severity
9.8CRITICALNVD
EPSS
0.0%
top 98.45%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMar 30
Latest updateMar 31

Description

An issue was discovered in Joomla! 4.0.0 through 4.1.0. Under specific circumstances, JInput pollutes method-specific input bags with $_REQUEST data.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HExploitability: 3.9 | Impact: 5.9

Affected Packages4 packages

CVEListV5joomla!_project/joomla_input2.0.0-2.0.1
Packagistjoomla/input2.0.02.0.2
NVDjoomla/joomla_!4.0.04.1.0
CVEListV5joomla!_project/joomla!_cms4.0.0-4.1.0

🔴Vulnerability Details

3
GHSA
Variable Tampering within joomla/input class2022-03-31
OSV
Variable Tampering within joomla/input class2022-03-31
CVEList
[20220307] - Core - Variable Tampering on JInput $_REQUEST data2022-03-30
CVE-2022-23799 — Joomla Input vulnerability | cvebase