« Volver al listado

CVE-2022-23794

Estado: ModificadaMedia (5.3)—

An issue was discovered in Joomla! 3.0.0 through 3.10.6 & 4.0.0 through 4.1.0. Uploading a file name of an excess length causes the error. This error brings up the screen with the path of the source code of the web application.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2022-23794",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 5,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:L/Au:N/C:P/I:N/A:N",
          "authentication": "NONE",
          "integrityImpact": "NONE",
          "accessComplexity": "LOW",
          "availabilityImpact": "NONE",
          "confidentialityImpact": "PARTIAL"
        },
        "acInsufInfo": false,
        "impactScore": 2.9,
        "baseSeverity": "MEDIUM",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 10,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 5.3,
          "attackVector": "NETWORK",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N",
          "integrityImpact": "NONE",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "LOW"
        },
        "impactScore": 1.4,
        "exploitabilityScore": 3.9
      }
    ]
  },
  "affected": [
    {
      "source": "security@joomla.org",
      "affectedData": [
        {
          "vendor": "Joomla! Project",
          "product": "Joomla! CMS",
          "versions": [
            {
              "status": "affected",
              "version": "3.0.0-3.10.6 & 4.0.0-4.1.0"
            }
          ]
        },
        {
          "vendor": "Joomla! Project",
          "product": "joomla/filesystem",
          "versions": [
            {
              "status": "affected",
              "version": "1.0.0-1.6.1 & 2.0.0"
            }
          ]
        }
      ]
    }
  ],
  "published": "2022-03-30T16:15:11.487",
  "references": [
    {
      "url": "https://developer.joomla.org/security-centre/871-20220302-core-path-disclosure-within-filesystem-error-messages.html",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "security@joomla.org"
    },
    {
      "url": "https://developer.joomla.org/security-centre/871-20220302-core-path-disclosure-within-filesystem-error-messages.html",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-209"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "An issue was discovered in Joomla! 3.0.0 through 3.10.6 & 4.0.0 through 4.1.0. Uploading a file name of an excess length causes the error. This error brings up the screen with the path of the source code of the web application."
    },
    {
      "lang": "es",
      "value": "Se ha detectado un problema en Joomla! Versiones 3.0.0 hasta 3.10.6 y 4.0.0 hasta 4.1.0. Subir un nombre de archivo con una longitud excesiva causa el error. Este error hace que aparezca la pantalla con la ruta del código fuente de la aplicación web"
    }
  ],
  "lastModified": "2026-06-17T04:30:47.437",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:joomla:joomla\\!:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "1358EA00-5DDD-4A6F-B63B-46F9FD39DABA",
              "versionEndIncluding": "3.10.6",
              "versionStartIncluding": "3.0.0"
            },
            {
              "criteria": "cpe:2.3:a:joomla:joomla\\!:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "73E200A2-6A45-47D7-B75E-5BD5F1B5778F",
              "versionEndIncluding": "4.1.0",
              "versionStartIncluding": "4.0.0"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "security@joomla.org"
}