CVE-2015-7859: Infoleak
Published Oct 29, 2015
·Updated
The comcontenthistory component in Joomla! 3.2 before 3.4.5 does not properly check ACLs, which allows remote attackers to obtain sensitive information via unspecified vectors.
Affected Software
15 affected components
Joomla Joomla\!=3.2.0
Joomla Joomla\!=3.2.1
Joomla Joomla\!=3.2.2
Joomla Joomla\!=3.2.3
Joomla Joomla\!=3.2.4
Joomla Joomla\!=3.3.0
Joomla Joomla\!=3.3.1
Joomla Joomla\!=3.3.2
Joomla Joomla\!=3.3.3
Joomla Joomla\!=3.3.4
Joomla Joomla\!=3.4.0
Joomla Joomla\!=3.4.1
Joomla Joomla\!=3.4.2
Joomla Joomla\!=3.4.3
Joomla Joomla\!=3.4.4
Event History
Oct 29, 2015
CVE Published
via MITRE·08:00 PM
Data Sourced
via MITRE·08:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2015-7859?
CVE-2015-7859 is rated as a medium severity vulnerability due to its potential for information disclosure.
2
How do I fix CVE-2015-7859?
To fix CVE-2015-7859, update Joomla to version 3.4.5 or later where the ACL checks have been improved.
3
What kind of information can be exposed due to CVE-2015-7859?
CVE-2015-7859 allows remote attackers to potentially access sensitive information that is not properly restricted by access control settings.
4
Which Joomla versions are affected by CVE-2015-7859?
Joomla versions 3.2.0 to 3.4.4 are vulnerable to CVE-2015-7859.
5
Is there a workaround for CVE-2015-7859?
There are no officially recommended workarounds for CVE-2015-7859; the best course of action is to upgrade to a secure version.