CERT-In Vulnerability Note
CIVN-2019-0187
Information Disclosure Vulnerability in Joomla
Original Issue Date:November 26, 2019
Severity Rating: MEDIUM
Software Affected
- Joomla CMS versions 3.6.0 through 3.9.12
Overview
A vulnerability has been reported in Joomla which could be exploited by a remote attacker to obtain potentially sensitive information on a targeted system.
Description
This vulnerability exists in phputf8 mapping files of Joomla due to improper access checks. A remote attacker could gain information about file system structure of the server where the website is hosted.
Successful exploitation of this vulnerability could allow the attacker to obtain sensitive information of the target system which could lead to further attacks.
Solution
- Upgrade to Joomla CMS version 3.9.13
Vendor Information
Joomla
https://developer.joomla.org/security-centre/795-20191002-core-path-disclosure-in-phpuft8-mapping-files.html
References
Symantec
https://www.symantec.com/security-center/vulnerabilities/writeup/110766
Joomla
https://developer.joomla.org/security-centre/795-20191002-core-path-disclosure-in-phpuft8-mapping-files.html
CVE Name
CVE-2019-18674
Disclaimer
The information provided herein is on "as is" basis, without warranty of any kind.
Contact Information
Email: info@cert-in.org.in Phone: +91-11-24368572
Postal address
Indian Computer Emergency Response Team (CERT-In) Ministry of Electronics and Information Technology Government of India Electronics Niketan 6, CGO Complex, Lodhi Road, New Delhi - 110 003 India
|