CVE-2020-35611

HIGH

Joomla! 2.5.0-3.9.22 - Unauthenticated Exposure of Sensitive Information in Global Configuration Page

Title source: llm
STIX 2.1

Description

An issue was discovered in Joomla! 2.5.0 through 3.9.22. The globlal configuration page does not remove secrets from the HTML output, disclosing the current values.

References (1)

Core 1

Scores

CVSS v3 7.5
EPSS 0.0001
EPSS Percentile 1.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Details

CWE
CWE-200
Status published
Products (1)
joomla/joomla\! 2.5.0 - 3.9.22
Published Dec 28, 2020
Tracked Since Feb 18, 2026