PT-2022-16266 · Joomla · Joomla!

Dangkhai

·

Published

2022-03-30

·

Updated

2025-04-03

·

CVE-2022-23794

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Joomla! versions 3.0.0 through 3.10.6 Joomla! versions 4.0.0 through 4.1.0
Description An issue was discovered where uploading a file with an excessively long name causes an error. This error results in the display of the web application's source code path.
Recommendations For Joomla! versions 3.0.0 through 3.10.6, update to a version outside of this range to resolve the issue. For Joomla! versions 4.0.0 through 4.1.0, update to a version outside of this range to resolve the issue. As a temporary workaround, consider restricting file uploads to prevent exploitation until a patch is available.

Exploit

Fix

Generation of Error Message Containing Sensitive Information

Weakness Enumeration

Related Identifiers

BIT-JOOMLA-2022-23794
CVE-2022-23794
GHSA-RC8Q-45V8-X6XC

Affected Products

Joomla!