First published: Tue Mar 29 2022(Updated: )
An issue was discovered in Joomla! 3.0.0 through 3.10.6 & 4.0.0 through 4.1.0. Uploading a file name of an excess length causes the error. This error brings up the screen with the path of the source code of the web application.
Credit: security@joomla.org security@joomla.org
Affected Software | Affected Version | How to fix |
---|---|---|
composer/joomla/filesystem | <1.6.2>=2.0.0<2.0.1 | |
Joomla Joomla\! | >=3.0.0<=3.10.6 | |
Joomla Joomla\! | >=4.0.0<=4.1.0 | |
composer/joomla/filesystem | >=2.0.0<2.0.1 | 2.0.1 |
composer/joomla/filesystem | <1.6.2 | 1.6.2 |
>=3.0.0<=3.10.6 | ||
>=4.0.0<=4.1.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2022-23794.
The severity of CVE-2022-23794 is medium, with a severity value of 5.3.
CVE-2022-23794 is a vulnerability in Joomla! versions 3.0.0 through 3.10.6 & 4.0.0 through 4.1.0 that allows path disclosure, revealing the source code path of the web application.
Joomla! versions 3.0.0 through 3.10.6 and 4.0.0 through 4.1.0 are affected by CVE-2022-23794.
To fix CVE-2022-23794, you should update Joomla! to version 3.10.7 or 4.1.1 or later.