8.1
CVSSv3

CVE-2015-4075

Published: 20/09/2017 Updated: 16/10/2019
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
CVSS v3 Base Score: 8.1 | Impact Score: 5.9 | Exploitability Score: 2.2
VMScore: 685
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

The Helpdesk Pro plugin prior to 1.4.0 for Joomla! allows remote malicious users to write to arbitrary .ini files via a crafted language.save task.

Vulnerable Product Search on Vulmon Subscribe to Product

helpdeskpro helpdesk pro

Exploits

Document Title ============== Joomla! plugin Helpdesk Pro < 140 Reported By =========== Simon Rawet from Outpost24 Kristian Varnai from Outpost24 Gregor Mynarsky from Outpost24 wwwoutpost24com/ For full details, see; wwwoutpost24com/outpost24-has-found-critical-vulnerabilities-in-joomla-helpdesk-pro/ Tested on ========= ...
Joomla Helpdesk Pro versions prior to 140 suffers from cross site scripting, local file disclosure, remote file upload, remote SQL injection, and insecure direct object reference vulnerabilities ...