The Joomanager component through 2.0.0 for Joomla! has an arbitrary file download issue, resulting in exposing the credentials of the database via an index.php?option=com_joomanager&controller=details&task=download&path=configuration.php request.
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
Link | Tags |
---|---|
https://vel.joomla.org/vel-blog/2020-joomanager-2-0-0-other | mitigation vendor advisory |
https://www.exploit-db.com/exploits/44252 | third party advisory vdb entry exploit |
https://cxsecurity.com/issue/WLB-2018030054 | third party advisory exploit |