VulnerabilityModified
CVE-2012-1599
1.5.x before 1.5.26 does not properly check permissions, which allows attackers to obtain sensitive "administrative back end information" via unknown vectors.
MEDIUM 5.0EPSS 0.98%
Does this matter?
Lower severity and a low EPSS score (0.98%). Track it; it rarely justifies an emergency change on its own.
Description
Joomla! 1.5.x before 1.5.26 does not properly check permissions, which allows attackers to obtain sensitive "administrative back end information" via unknown vectors. NOTE: this might be a duplicate of CVE-2012-1611.
- CVSS 2.0
- 5.0 MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
- EPSS
- 0.98% probability · 60th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-264
- Affected
- joomla/joomla\!
- Source
- secalert@redhat.com
References
- http://developer.joomla.org/security/news/397-20120306-core-information-disclosure.htmlVendor Advisory
- http://www.openwall.com/lists/oss-security/2012/03/29/5
- http://developer.joomla.org/security/news/397-20120306-core-information-disclosure.htmlVendor Advisory
- http://www.openwall.com/lists/oss-security/2012/03/29/5
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.