CVE-2017-18345
The Joomanager component through 2.0.0 for Joomla!
CRITICAL
joomanager
Composant
Description
The Joomanager component through 2.0.0 for Joomla! has an arbitrary file download issue, resulting in exposing the credentials of the database via an index.php?option=com_joomanager&controller=details&task=download&path=configuration.php request.
Sévérité
9.8
Critique · CVSS 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Score retenu : NVD
| Source | Sévérité d'origine | CVSS |
|---|---|---|
| NVD | CRITICAL | 9.8 (v3.0) |
Produit et versions
- Produit
- joomanager
- Type
- Composant
- Corrigée dans
- Non précisée
- Publiée
- 26/08/2018
- Modifiée
- 17/06/2026
- CWE
- CWE-200
Versions concernées
- joomanager — jusqu'à 2.0.0
Sources
- NVD CVE-2017-18345 vu
Ces informations proviennent des sources ci-dessus ; CVE Oyer n'y ajoute aucune interprétation.
Historique
- Détectée via nvd26/09/2026 09:34 UTC