CVE-2022-27912: [20221001] - Core - Debug Mode leaks full request payloads including passwords
Published Oct 25, 2022
·Updated
An issue was discovered in Joomla! 4.0.0 through 4.2.3. Sites with publicly enabled debug mode exposed data of previous requests.
Affected Software
1 affected component
Joomla Joomla\!>=4.0.0<=4.2.3
Event History
Oct 25, 2022
CVE Published
via MITRE·07:00 PM
Data Sourced
via MITRE·07:00 PM
DescriptionWeakness
Frequently Asked Questions
1
What is CVE-2022-27912?
CVE-2022-27912 is a vulnerability discovered in Joomla! 4.0.0 through 4.2.3 that exposes data of previous requests on sites with publicly enabled debug mode.
2
How severe is CVE-2022-27912?
CVE-2022-27912 has a severity keyword of medium and a severity value of 5.3.
3
How does CVE-2022-27912 affect Joomla!?
CVE-2022-27912 affects Joomla! versions 4.0.0 through 4.2.3 specifically when debug mode is publicly enabled, exposing data of previous requests.
4
Is there a fix available for CVE-2022-27912?
Yes, a fix is available for CVE-2022-27912. It is recommended to update Joomla! to version 4.2.4 or later to mitigate the vulnerability.
5
Where can I find more information about CVE-2022-27912?
More information about CVE-2022-27912 can be found on the official Joomla! Security Centre website.