CVE-2019-7743: Critical severity joomla vulnerability
An issue was discovered in Joomla! before 3.9.3. The phar:// stream wrapper can be used for object injection attacks because there is no protection mechanism (such as the TYPO3 PHAR stream wrapper) to prevent use of the phar:// handler for non .phar-files.
Other sources
An issue was discovered in Joomla! before 3.9.3. The phar:// stream wrapper can be used for objection injection attacks because there is no protection mechanism (such as the TYPO3 PHAR stream wrapper) to prevent use of the phar:// handler for non .phar-files.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2019-7743?
CVE-2019-7743 is classified as a high-severity vulnerability due to its potential for object injection attacks.
How do I fix CVE-2019-7743?
To fix CVE-2019-7743, upgrade Joomla! to version 3.9.3 or later.
What software versions are affected by CVE-2019-7743?
CVE-2019-7743 affects Joomla! versions prior to 3.9.3, including all versions from 2.5.0 to 3.9.2.
What type of attack does CVE-2019-7743 enable?
CVE-2019-7743 enables object injection attacks via the phar:// stream wrapper.
Is there a known exploit for CVE-2019-7743?
While specific exploits for CVE-2019-7743 have not been publicly disclosed, the vulnerability's nature poses a high risk for exploitation.