CVE-2019-7743

CRITICAL9.8EPSS 1.0%

Joomla! Object Injection Vulnerability

Published: 5/13/2022Modified: 11/8/2023
Also known as:GHSA-5m3w-rvvh-8fx6

Description

An issue was discovered in Joomla! before 3.9.3. The phar:// stream wrapper can be used for object injection attacks because there is no protection mechanism (such as the TYPO3 PHAR stream wrapper) to prevent use of the phar:// handler for non .phar-files.

Affected packages (1)

CVSS scores

SourceVersionSeverityVector
osvCVSS 3.1CRITICAL9.8CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

References (5)