CVE-2020-35611

HIGH7.5EPSS 0.01%

[20201102] - Core - Disclosure of secrets in Global Configuration page

Published: 4/3/2025Modified: 5/20/2025

Description

An issue was discovered in Joomla! 2.5.0 through 3.9.22. The globlal configuration page does not remove secrets from the HTML output, disclosing the current values.

Affected packages (1)

CVSS scores

SourceVersionSeverityVector
osvCVSS 3.1HIGH7.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

References (2)