« Back to list

CVE-2009-3945

Status: ModifiedMedium (5.5)—

Unspecified vulnerability in the Front-End Editor in the com_content component in Joomla! before 1.5.15 allows remote authenticated users, with Author privileges, to replace the articles of an arbitrary user via unknown vectors.

CVSS

Exploitation probability (EPSS)

EPSS (Exploit Prediction Scoring System, FIRST) estimates how likely a vulnerability is to be exploited in the wild within 30 days. It complements CVSS (impact) and CISA KEV (confirmed exploitation).

Affected technologies (1)

CWEs

References

Raw JSON (NVD)

Show
{
  "id": "CVE-2009-3945",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 5.5,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:L/Au:S/C:N/I:P/A:P",
          "authentication": "SINGLE",
          "integrityImpact": "PARTIAL",
          "accessComplexity": "LOW",
          "availabilityImpact": "PARTIAL",
          "confidentialityImpact": "NONE"
        },
        "acInsufInfo": true,
        "impactScore": 4.9,
        "baseSeverity": "MEDIUM",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 8,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ]
  },
  "affected": [
    {
      "source": "cve@mitre.org",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "n/a",
          "versions": [
            {
              "status": "affected",
              "version": "n/a"
            }
          ]
        }
      ]
    }
  ],
  "published": "2009-11-16T20:30:00.217",
  "references": [
    {
      "url": "http://developer.joomla.org/security/news/305-20091103-core-front-end-editor-issue-.html",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "http://osvdb.org/59801",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://secunia.com/advisories/37262",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/54161",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://developer.joomla.org/security/news/305-20091103-core-front-end-editor-issue-.html",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://osvdb.org/59801",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://secunia.com/advisories/37262",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/54161",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "NVD-CWE-noinfo"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Unspecified vulnerability in the Front-End Editor in the com_content component in Joomla! before 1.5.15 allows remote authenticated users, with Author privileges, to replace the articles of an arbitrary user via unknown vectors."
    },
    {
      "lang": "es",
      "value": "Vulnerabilidad no especificada en el Front-End Editor del componente com_content en Joomla! versiones anteriores a v1.5.15 permite a usuarios autenticados remotamente, con privilegios \"Author\", reemplazar los artículos de un usuario de su elección mediante vectores desconocidos."
    }
  ],
  "lastModified": "2026-06-16T23:12:40.697",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:joomla:joomla\\!:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "CF58B3CE-F953-487D-A1E9-E484A4F37E5D",
              "versionEndIncluding": "1.5.14"
            },
            {
              "criteria": "cpe:2.3:a:joomla:joomla\\!:1.5.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "65184BFE-A070-4099-B672-3A238E9F83EF"
            },
            {
              "criteria": "cpe:2.3:a:joomla:joomla\\!:1.5.1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "920129E4-F979-49B5-9B96-62BCBC3954D5"
            },
            {
              "criteria": "cpe:2.3:a:joomla:joomla\\!:1.5.2:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "1313BEAD-C0C0-4D8C-A3AA-F514BA6A1C92"
            },
            {
              "criteria": "cpe:2.3:a:joomla:joomla\\!:1.5.3:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "A90A8900-E441-46C4-A725-BA312358760E"
            },
            {
              "criteria": "cpe:2.3:a:joomla:joomla\\!:1.5.4:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "E74E276C-C62D-4828-89CB-80F526FEAEA5"
            },
            {
              "criteria": "cpe:2.3:a:joomla:joomla\\!:1.5.5:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "F370EA7F-3719-4D35-A7FD-C7AD1BD709D5"
            },
            {
              "criteria": "cpe:2.3:a:joomla:joomla\\!:1.5.6:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "E4E48636-9EDB-49BB-ABC8-D79864BFCB38"
            },
            {
              "criteria": "cpe:2.3:a:joomla:joomla\\!:1.5.7:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "580712F4-E97C-4E3F-BF9D-3445BEB4C3FE"
            },
            {
              "criteria": "cpe:2.3:a:joomla:joomla\\!:1.5.8:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "466E5E84-4C69-49F2-83DA-FC86202DB7F4"
            },
            {
              "criteria": "cpe:2.3:a:joomla:joomla\\!:1.5.9:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "CB968DF7-4A0B-474C-8639-06976837E03D"
            },
            {
              "criteria": "cpe:2.3:a:joomla:joomla\\!:1.5.10:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "1B6BE010-649F-4E48-97DC-DDF7511406D5"
            },
            {
              "criteria": "cpe:2.3:a:joomla:joomla\\!:1.5.11:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "2B8C4094-D028-4A55-B523-C90F5A4C9D82"
            },
            {
              "criteria": "cpe:2.3:a:joomla:joomla\\!:1.5.12:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "69FA6550-2135-4D41-B592-433FFFDEE180"
            },
            {
              "criteria": "cpe:2.3:a:joomla:joomla\\!:1.5.13:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "C73D78E0-BF24-433B-9F1B-03FD956C5779"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "cve@mitre.org"
}