VulnerabilityModified
CVE-2012-2747
Unspecified vulnerability in Joomla!
HIGH 7.5EPSS 2.28%
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (2.28%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Unspecified vulnerability in Joomla! 2.5.x before 2.5.5 allows remote attackers to gain privileges via unknown attack vectors related to "Inadequate checking."
- CVSS 2.0
- 7.5 HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
- EPSS
- 2.28% probability · 82th percentile
- CISA KEV
- Not listed
- Affected
- joomla/joomla\!
- Source
- secalert@redhat.com
References
- http://developer.joomla.org/security/news/470-20120601-core-privilege-escalationVendor Advisory
- http://osvdb.org/83070Broken Link
- http://secunia.com/advisories/49605Third Party Advisory
- http://www.joomla.org/announcements/release-news/5427-joomla-255-released.htmlVendor Advisory
- http://www.openwall.com/lists/oss-security/2012/06/19/2Mailing List, Third Party Advisory
- http://www.securityfocus.com/bid/54073Third Party Advisory, VDB Entry
- https://exchange.xforce.ibmcloud.com/vulnerabilities/76415Third Party Advisory, VDB Entry
- http://developer.joomla.org/security/news/470-20120601-core-privilege-escalationVendor Advisory
- http://osvdb.org/83070Broken Link
- http://secunia.com/advisories/49605Third Party Advisory
- http://www.joomla.org/announcements/release-news/5427-joomla-255-released.htmlVendor Advisory
- http://www.openwall.com/lists/oss-security/2012/06/19/2Mailing List, Third Party Advisory
- http://www.securityfocus.com/bid/54073Third Party Advisory, VDB Entry
- https://exchange.xforce.ibmcloud.com/vulnerabilities/76415Third Party Advisory, VDB Entry
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.