
CVE-2020-35612 – [20201103] - Core - Path traversal in mod_random_image
https://notcve.org/view.php?id=CVE-2020-35612
28 Dec 2020 — An issue was discovered in Joomla! 2.5.0 through 3.9.22. The folder parameter of mod_random_image lacked input validation, leading to a path traversal vulnerability. Se detectó un problema en Joomla! versiones 2.5.0 hasta 3.9.22. • https://developer.joomla.org/security-centre/830-20201103-core-path-traversal-in-mod-random-image.html • CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') •

CVE-2020-35611 – [20201102] - Core - Disclosure of secrets in Global Configuration page
https://notcve.org/view.php?id=CVE-2020-35611
28 Dec 2020 — An issue was discovered in Joomla! 2.5.0 through 3.9.22. The globlal configuration page does not remove secrets from the HTML output, disclosing the current values. Se detectó un problema en Joomla! versiones 2.5.0 hasta 3.9.22. • https://developer.joomla.org/security-centre/829-20201102-core-disclosure-of-secrets-in-global-configuration-page.html • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor •

CVE-2020-35610 – [20201101] - Core - com_finder ignores access levels on autosuggest
https://notcve.org/view.php?id=CVE-2020-35610
28 Dec 2020 — An issue was discovered in Joomla! 2.5.0 through 3.9.22. The autosuggestion feature of com_finder did not respect the access level of the corresponding terms. Se detectó un problema en Joomla! versiones 2.5.0 hasta 3.9.22. • https://developer.joomla.org/security-centre/828-20201101-core-com-finder-ignores-access-levels-on-autosuggest.html •

CVE-2020-24598
https://notcve.org/view.php?id=CVE-2020-24598
26 Aug 2020 — An issue was discovered in Joomla! before 3.9.21. Lack of input validation in the vote feature of com_content leads to an open redirect. Se detectó un problema en Joomla! versiones anteriores a 3.9.21. • https://developer.joomla.org/security-centre/825-20200802-core-open-redirect-in-com-content-vote-feature • CWE-601: URL Redirection to Untrusted Site ('Open Redirect') •

CVE-2020-24599
https://notcve.org/view.php?id=CVE-2020-24599
26 Aug 2020 — An issue was discovered in Joomla! before 3.9.21. Lack of escaping in mod_latestactions allows XSS attacks. Se detectó un problema en Joomla! versiones anteriores a 3.9.21. • https://developer.joomla.org/security-centre/824-20200801-core-xss-in-mod-latestactions • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVE-2020-15700
https://notcve.org/view.php?id=CVE-2020-15700
15 Jul 2020 — An issue was discovered in Joomla! through 3.9.19. A missing token check in the ajax_install endpoint of com_installer causes a CSRF vulnerability. Se detectó un problema en Joomla! versiones hasta el 3.9.19. • https://developer.joomla.org/security-centre/818-20200701-core-csrf-in-com-installer-ajax-install-endpoint.html • CWE-352: Cross-Site Request Forgery (CSRF) •

CVE-2020-15699
https://notcve.org/view.php?id=CVE-2020-15699
15 Jul 2020 — An issue was discovered in Joomla! through 3.9.19. Missing validation checks on the usergroups table object can result in a broken site configuration. Se detectó un problema en Joomla! versiones hasta el 3.9.19. • https://developer.joomla.org/security-centre/819-20200702-core-missing-checks-can-lead-to-a-broken-usergroups-table-record.html • CWE-345: Insufficient Verification of Data Authenticity •

CVE-2020-15698
https://notcve.org/view.php?id=CVE-2020-15698
15 Jul 2020 — An issue was discovered in Joomla! through 3.9.19. Inadequate filtering on the system information screen could expose Redis or proxy credentials Se detectó un problema en Joomla! versiones hasta el 3.9.19. Un filtrado inadecuado en la pantalla de información del sistema podría exponer las credenciales de Redis o del proxy • https://developer.joomla.org/security-centre/823-20200706-core-system-information-screen-could-expose-redis-or-proxy-credentials.html •

CVE-2020-15697
https://notcve.org/view.php?id=CVE-2020-15697
15 Jul 2020 — An issue was discovered in Joomla! through 3.9.19. Internal read-only fields in the User table class could be modified by users. Se detectó un problema en Joomla! versiones hasta el 3.9.19. • https://developer.joomla.org/security-centre/821-20200704-core-variable-tampering-via-user-table-class.html • CWE-732: Incorrect Permission Assignment for Critical Resource •

CVE-2020-15696
https://notcve.org/view.php?id=CVE-2020-15696
15 Jul 2020 — An issue was discovered in Joomla! through 3.9.19. Lack of input filtering and escaping allows XSS attacks in mod_random_image. Se detectó un problema en Joomla! versiones hasta el 3.9.19. • https://developer.joomla.org/security-centre/822-20200705-core-escape-mod-random-image-link.html • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •