extensions.joomla.org
https://extensions.joomla.org/extension/je-messenger CVE-2019-9922
HIGHNuclei
Joomla! Harmis Messenger 1.2.2 - Local File Inclusion
Record summary
CVE-2019-9922 has a selected CVSS score of 7.5 (high); EIP currently links 1 Nuclei template.
Description
An issue was discovered in the Harmis JE Messenger component 1.2.2 for Joomla!. Directory Traversal allows read access to arbitrary files.
Description source: CVE List
Exploitation context
Available material
- Nuclei templates
- 1
Nuclei templates
1ProjectDiscoveryHIGHJoomla! Harmis Messenger 1.2.2 - Local File InclusionCVSS 7.5
Joomla! Harmis Messenger 1.2.2 is vulnerable to local file inclusion which could give an attacker read access to arbitrary files.
Impact
Successful exploitation of this vulnerability can lead to unauthorized access to sensitive files, remote code execution, and potential compromise of the entire Joomla! application.
Remediation
Update to the latest version of Harmis Messenger (1.2.3) or apply the patch provided by the vendor to fix the LFI vulnerability.
WeaknessesCWE-22
Authors0x_Akoko
Template tagscve2019cvejoomlamessengerlfiharmistechnologyvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CPE: cpe:2.3:a:harmistechnology:je_messenger:1.2.2:*:*:*:*:joomla\!:*:*
https://github.com/azd-cert/CVE/blob/master/CVEs/CVE-2019-9922.md https://extensions.joomla.org/extension/je-messenger/ https://nvd.nist.gov/vuln/detail/CVE-2019-9922 https://github.com/ARPSyndicate/kenzer-templates https://github.com/azd-cert/CVE
Source: ProjectDiscovery
References
3github.com
https://github.com/azd-cert/CVE/blob/master/CVEs/CVE-2019-9922.md nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2019-9922