CVE-2017-14595

LOW

Joomla! - Information Disclosure via Archived Article SQL Query

Title source: llm
STIX 2.1

Description

In Joomla! before 3.8.0, a logic bug in a SQL query could lead to the disclosure of article intro texts when these articles are in the archived state.

References (3)

Core 3
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://www.securitytracker.com/id/1039407
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/100900

Scores

CVSS v3 3.7
EPSS 0.0003
EPSS Percentile 7.8%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N

Details

Status published
Products (6)
joomla/joomla\! 3.7.0
joomla/joomla\! 3.7.1
joomla/joomla\! 3.7.2
joomla/joomla\! 3.7.3
joomla/joomla\! 3.7.4
joomla/joomla\! 3.7.5
Published Sep 20, 2017
Tracked Since Feb 18, 2026