« Volver al listado

CVE-2022-27909

Estado: ModificadaMedia (4.3)—

In Joomla component 'jDownloads 3.9.8.2 Stable' the remote user can change some parameters in the address bar and see the names of other users' files

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2022-27909",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 4,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:L/Au:S/C:P/I:N/A:N",
          "authentication": "SINGLE",
          "integrityImpact": "NONE",
          "accessComplexity": "LOW",
          "availabilityImpact": "NONE",
          "confidentialityImpact": "PARTIAL"
        },
        "acInsufInfo": false,
        "impactScore": 2.9,
        "baseSeverity": "MEDIUM",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 8,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 4.3,
          "attackVector": "NETWORK",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N",
          "integrityImpact": "NONE",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "LOW"
        },
        "impactScore": 1.4,
        "exploitabilityScore": 2.8
      }
    ]
  },
  "affected": [
    {
      "source": "security@joomla.org",
      "affectedData": [
        {
          "vendor": "jDownloads",
          "product": "jDownloads",
          "versions": [
            {
              "status": "affected",
              "version": "<=3.9.8.2"
            }
          ]
        }
      ]
    }
  ],
  "published": "2022-05-06T18:15:09.957",
  "references": [
    {
      "url": "https://hackerhood.redhotcyber.com/cve-2022-27909-jdownloads/",
      "tags": [
        "Third Party Advisory"
      ],
      "source": "security@joomla.org"
    },
    {
      "url": "https://www.jdownloads.com/index.php/downloads/download/57-jdownloads-3-9.html",
      "tags": [
        "Release Notes",
        "Vendor Advisory"
      ],
      "source": "security@joomla.org"
    },
    {
      "url": "https://hackerhood.redhotcyber.com/cve-2022-27909-jdownloads/",
      "tags": [
        "Third Party Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://www.jdownloads.com/index.php/downloads/download/57-jdownloads-3-9.html",
      "tags": [
        "Release Notes",
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "NVD-CWE-noinfo"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "In Joomla component 'jDownloads 3.9.8.2 Stable' the remote user can change some parameters in the address bar and see the names of other users' files"
    },
    {
      "lang": "es",
      "value": "En el componente de Joomla versión \"jDownloads 3.9.8.2 Stable\", el usuario remoto puede cambiar algunos parámetros en la barra de direcciones y visualizar los nombres de los archivos de otros usuarios"
    }
  ],
  "lastModified": "2026-06-17T04:37:43.800",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:jdownloads:jdownloads:3.9.8.2:*:*:*:*:joomla\\!:*:*",
              "vulnerable": true,
              "matchCriteriaId": "F3B29DC2-06E7-48B4-A3ED-08B338E2C895"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "security@joomla.org"
}