CVE-2017-14596

CRITICAL

Joomla! <3.8.0 - Info Disclosure

Title source: llm
STIX 2.1

Description

In Joomla! before 3.8.0, inadequate escaping in the LDAP authentication plugin can result in a disclosure of a username and password.

Scores

CVSS v3 9.8
EPSS 0.0257
EPSS Percentile 85.6%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-90
Status published
Products (50)
joomla/joomla\! 1.5.0
joomla/joomla\! 1.5.1
joomla/joomla\! 1.5.2
joomla/joomla\! 1.5.3
joomla/joomla\! 1.5.4
joomla/joomla\! 1.5.5
joomla/joomla\! 1.5.6
joomla/joomla\! 1.5.7
joomla/joomla\! 1.5.8
joomla/joomla\! 1.5.9
... and 40 more
Published Sep 20, 2017
Tracked Since Feb 18, 2026