CVE-2023-39974: Extension - acymailing.com - Exposure of Sensitive Information in AcyMailing Enterprise component for Joomla 6.7.0-8.6.3
Exposure of Sensitive Information vulnerability in AcyMailing Enterprise component for Joomla. It allows unauthorized actors to get the number of subscribers in a specific list.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2023-39974?
CVE-2023-39974 is a vulnerability that allows unauthorized actors to obtain the number of subscribers in a specific list in the AcyMailing Enterprise component for Joomla.
How does CVE-2023-39974 impact AcyMailing Enterprise component for Joomla?
CVE-2023-39974 exposes sensitive information and allows unauthorized actors to retrieve the number of subscribers in a specific list.
What is the severity of CVE-2023-39974?
The severity of CVE-2023-39974 is medium with a CVSS score of 5.3.
How can unauthorized actors exploit CVE-2023-39974?
Unauthorized actors can exploit CVE-2023-39974 to gather the number of subscribers in a specific list without proper authorization.
How can I mitigate CVE-2023-39974 in AcyMailing Enterprise component for Joomla?
To mitigate CVE-2023-39974, it is recommended to update AcyMailing Enterprise component to a version that is not vulnerable.