445
VMScore

CVE-2021-23123

Published: 12/01/2021 Updated: 19/01/2021
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
CVSS v3 Base Score: 5.3 | Impact Score: 1.4 | Exploitability Score: 3.9
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

An issue exists in Joomla! 3.0.0 up to and including 3.9.23. The lack of ACL checks in the orderPosition endpoint of com_modules leak names of unpublished and/or inaccessible modules.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

joomla joomla\\!

Github Repositories

Joomla RCE (CVE2021-23132) com_media allowed paths that are not intended for image uploads to RCE A vulnerability, which was classified as critical, has been found in Joomla! 300 through 3924 (Content Management System) This issue affects an unknown function of the component com_media The manipulation with an unknown input leads to a directory traversal vulnerability