CVE-2019-7743
Joomla! Object Injection Vulnerability
CRITICAL
Joomla CMS
Description
An issue was discovered in Joomla! before 3.9.3. The phar:// stream wrapper can be used for objection injection attacks because there is no protection mechanism (such as the TYPO3 PHAR stream wrapper) to prevent use of the phar:// handler for non .phar-files.
Sévérité
9.8
Critique · CVSS 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Score retenu : NVD
| Source | Sévérité d'origine | CVSS |
|---|---|---|
| NVD | CRITICAL | 9.8 (v3.0) |
| GitHub Advisories | critical | 9.8 (v3.0) |
| OSV | CRITICAL | 9.8 (v3.0) calculé |
Produit et versions
- Produit
- Joomla CMS
- Corrigée dans
- 3.9.3
- Publiée
- 12/02/2019
- Modifiée
- 17/06/2026
- CWE
- CWE-502, CWE-917
Versions concernées
- 2.5.0 – 3.9.3 (exclue)
Sources
- NVD CVE-2019-7743 vu
- GitHub Advisories GHSA-5m3w-rvvh-8fx6 vu
- OSV GHSA-5m3w-rvvh-8fx6 vu
Ces informations proviennent des sources ci-dessus ; CVE Oyer n'y ajoute aucune interprétation.
Historique
- Source ajoutée : nvd26/09/2026 09:34 UTC
- Source ajoutée : osv26/09/2026 09:27 UTC
- Détectée via github26/09/2026 09:27 UTC