CVE-2017-14595
low
CVSS v3
3.7
CVSS v2
4.3
VIR risk
3.7
Description
In Joomla! before 3.8.0, a logic bug in a SQL query could lead to the disclosure of article intro texts when these articles are in the archived state.
Predictions
Exploit likelihood
47%
Patch ETA
—
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
Vendor advisory: cve@mitre.org — https://developer.joomla.org/security-centre/710-20170901-core-information-disclosure
References
- http://www.securityfocus.com/bid/100900
- http://www.securitytracker.com/id/1039407
- https://developer.joomla.org/security-centre/710-20170901-core-information-disclosure
- http://www.securityfocus.com/bid/100900
- http://www.securitytracker.com/id/1039407
- https://developer.joomla.org/security-centre/710-20170901-core-information-disclosure
Verify integrity in audit chain (admin only). AS-IS.