CVE-2017-18345

Severity CVSS v4.0:
Pending analysis
Type:
CWE-200 Information Leak / Disclosure
Publication date:
26/08/2018
Last modified:
06/11/2018

Description

The Joomanager component through 2.0.0 for Joomla! has an arbitrary file download issue, resulting in exposing the credentials of the database via an index.php?option=com_joomanager&controller=details&task=download&path=configuration.php request.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:joomanager_project:joomanager:*:*:*:*:*:joomla\!:*:* 2.0.0 (including)