CVE-2015-7859

The com_contenthistory component in Joomla! 3.2 before 3.4.5 does not properly check ACLs, which allows remote attackers to obtain sensitive information via unspecified vectors.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:joomla:joomla\!:3.2.0:*:*:*:*:*:*:*
cpe:2.3:a:joomla:joomla\!:3.2.1:*:*:*:*:*:*:*
cpe:2.3:a:joomla:joomla\!:3.2.2:*:*:*:*:*:*:*
cpe:2.3:a:joomla:joomla\!:3.2.3:*:*:*:*:*:*:*
cpe:2.3:a:joomla:joomla\!:3.2.4:*:*:*:*:*:*:*
cpe:2.3:a:joomla:joomla\!:3.3.0:*:*:*:*:*:*:*
cpe:2.3:a:joomla:joomla\!:3.3.1:*:*:*:*:*:*:*
cpe:2.3:a:joomla:joomla\!:3.3.2:*:*:*:*:*:*:*
cpe:2.3:a:joomla:joomla\!:3.3.3:*:*:*:*:*:*:*
cpe:2.3:a:joomla:joomla\!:3.3.4:*:*:*:*:*:*:*
cpe:2.3:a:joomla:joomla\!:3.4.0:*:*:*:*:*:*:*
cpe:2.3:a:joomla:joomla\!:3.4.1:*:*:*:*:*:*:*
cpe:2.3:a:joomla:joomla\!:3.4.2:*:*:*:*:*:*:*
cpe:2.3:a:joomla:joomla\!:3.4.3:*:*:*:*:*:*:*
cpe:2.3:a:joomla:joomla\!:3.4.4:*:*:*:*:*:*:*

History

21 Nov 2024, 02:37

Type Values Removed Values Added
References () http://developer.joomla.org/security-centre/629-20151002-core-acl-violations.html - () http://developer.joomla.org/security-centre/629-20151002-core-acl-violations.html -
References () http://www.securitytracker.com/id/1033950 - () http://www.securitytracker.com/id/1033950 -

Information

Published : 2015-10-29 20:59

Updated : 2024-11-21 02:37


NVD link : CVE-2015-7859

Mitre link : CVE-2015-7859

CVE.ORG link : CVE-2015-7859


JSON object : View

Products Affected

joomla

  • joomla\!
CWE
CWE-200

Exposure of Sensitive Information to an Unauthorized Actor