CVE-2022-23802: Extension - Insecure Permissions within Joomla Guru extensions
Joomla Guru extension 5.2.5 is affected by: Insecure Permissions. The impact is: obtain sensitive information (remote). The component is: Access to private information and components, possibility to view other users' information. Information disclosure Access to private information and components, possibility to view other users' information.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2022-23802?
CVE-2022-23802 has a moderate severity as it allows unauthorized access to sensitive information.
How do I fix CVE-2022-23802?
To fix CVE-2022-23802, update the Joomla Guru extension to the latest version.
What types of information can be exposed due to CVE-2022-23802?
CVE-2022-23802 can expose private information, including sensitive user data.
Who is affected by CVE-2022-23802?
Users of the Joomla Guru extension version 5.2.5 are affected by CVE-2022-23802.
What component is responsible for the weakness in CVE-2022-23802?
The weakness in CVE-2022-23802 is due to insecure permissions in the Joomla Guru extension.