CVE-2024-27185HTTP Request Smuggling in Joomla !

Severity
9.1CRITICALNVD
EPSS
0.0%
top 98.95%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedAug 20

Description

The pagination class includes arbitrary parameters in links, leading to cache poisoning attack vectors.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:HExploitability: 3.9 | Impact: 5.2

Affected Packages2 packages

NVDjoomla/joomla_!3.0.03.10.17+2
CVEListV5joomla!_project/joomla!_cms3.0.0-3.10.16, 4.0.0-4.4.6, 5.0.0-5.1.2+2

🔴Vulnerability Details

2
CVEList
[20240802] - Core - Cache Poisoning in Pagination2024-08-20
GHSA
GHSA-q677-7pjp-5hq5: The pagination class includes arbitrary parameters in links, leading to cache poisoning attack vectors2024-08-20
CVE-2024-27185 — HTTP Request Smuggling in Joomla ! | cvebase