Official Product Homepageproduct
http://joomboost.com/ CVE-2019-25762
HIGH
Joomla! Component JoomProject 1.1.3.2 Information Disclosure
Record summary
CVE-2019-25762 has a selected CVSS score of 8.7 (high); EIP currently links 1 catalogued exploit.
Description
Joomla! Component JoomProject 1.1.3.2 contains an information disclosure vulnerability that allows unauthenticated attackers to access sensitive user data by exploiting the projects endpoint. Attackers can send requests to index.php with option=com_jpprojects&view=projects&tmpl=component&format=json parameters to retrieve user IDs, names, and email addresses in JSON format.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
CISA SSVC decision
ExploitationPoC
AutomatableYes
Technical impactPartial
CISA Coordinator · SSVC 2.0.3 · Evaluated Jun 22, 2026 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
JoomProjectBrowse Joomboost / JoomProject | CVE List | 1.1.3.2 | affected |
Proofs of concept
1Catalogued exploits
ExploitDBJoomla! Component JoomProject 1.1.3.2 - Information DisclosureExploitDB exploitby Ihsan SencanNot analyzed1 file
References
5Product Referenceproduct
https://extensions.joomla.org/extensions/extension/clients-a-communities/project-a-task-management/joomproject nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2019-25762 ExploitDB-46121exploit
https://www.exploit-db.com/exploits/46121 VulnCheck Advisory: Joomla! Component JoomProject 1.1.3.2 Information DisclosureThird-party advisory
https://www.vulncheck.com/advisories/joomla-component-joomproject-information-disclosure