Vulnerabilities > CVE-2019-7739 - Unspecified vulnerability in Joomla Joomla!
Attack vector
NETWORK Attack complexity
LOW Privileges required
NONE Confidentiality impact
LOW Integrity impact
LOW Availability impact
NONE Summary
An issue was discovered in Joomla! before 3.9.3. The "No Filtering" textfilter overrides child settings in the Global Configuration. This is intended behavior. However, it might be unexpected for the user because the configuration dialog lacks an additional message to explain this.
Vulnerable Configurations
Nessus
NASL family | CGI abuses |
NASL id | JOOMLA_393.NASL |
description | According to its self-reported version number, the Joomla! installation running on the remote web server is prior to 3.9.3. It is, therefore, affected by multiple vulnerabilities: - An object injection vulnerability exists in Joomla! prior to 3.9.3 due to the absence of a protection mechanism to prevent the use of the phar:// handler for non .phar files. An unauthenticated, remote attacker can exploit this to include arbitrary files (CVE-2019-7743). - A cross-site scripting (XSS) vulnerability exists due to improper validation of user-supplied input before returning it to users. An unauthenticated, remote attacker can exploit this, by convincing a user to click a specially crafted URL, to execute arbitrary script code in a user |
last seen | 2020-06-01 |
modified | 2020-06-02 |
plugin id | 122346 |
published | 2019-02-20 |
reporter | This script is Copyright (C) 2019 and is owned by Tenable, Inc. or an Affiliate thereof. |
source | https://www.tenable.com/plugins/nessus/122346 |
title | Joomla! 2.5.0 < 3.9.3 Multiple Vulnerabilities |
code |
|
References
- http://www.securityfocus.com/bid/107015
- https://developer.joomla.org/security-centre/767-20190203-core-additional-warning-in-the-global-configuration-textfilter-settings
- http://www.securityfocus.com/bid/107015
- https://developer.joomla.org/security-centre/767-20190203-core-additional-warning-in-the-global-configuration-textfilter-settings