Vulnerability Details CVE-2019-25762
Joomla! Component JoomProject 1.1.3.2 contains an information disclosure vulnerability that allows unauthenticated attackers to access sensitive user data by exploiting the projects endpoint. Attackers can send requests to index.php with option=com_jpprojects&view=projects&tmpl=component&format=json parameters to retrieve user IDs, names, and email addresses in JSON format.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.006
EPSS Ranking 48.9%
CVSS Severity
CVSS v3 Score 7.5
Products affected by CVE-2019-25762
-
cpe:2.3:a:joomboost:joomproject:1.1.3.2