VulnerabilityModified
CVE-2012-1611
2.5.x before 2.5.4 does not properly check permissions, which allows attackers to obtain sensitive "administrative back end" information via unknown attack vectors.
MEDIUM 5.0EPSS 1.17%
Does this matter?
Lower severity and a low EPSS score (1.17%). Track it; it rarely justifies an emergency change on its own.
Description
Joomla! 2.5.x before 2.5.4 does not properly check permissions, which allows attackers to obtain sensitive "administrative back end" information via unknown attack vectors. NOTE: this might be a duplicate of CVE-2012-1599.
- CVSS 2.0
- 5.0 MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
- EPSS
- 1.17% probability · 66th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-264
- Affected
- joomla/joomla\!
- Source
- secalert@redhat.com
References
- http://developer.joomla.org/security/news/398-20120307-core-information-disclosure.htmlVendor Advisory
- http://secunia.com/advisories/48683Vendor Advisory
- http://www.openwall.com/lists/oss-security/2012/04/03/3
- http://www.openwall.com/lists/oss-security/2012/04/03/5
- http://developer.joomla.org/security/news/398-20120307-core-information-disclosure.htmlVendor Advisory
- http://secunia.com/advisories/48683Vendor Advisory
- http://www.openwall.com/lists/oss-security/2012/04/03/3
- http://www.openwall.com/lists/oss-security/2012/04/03/5
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.