CVE-2019-7743 is a critical vulnerability affecting Joomla! versions prior to 3.9.3, stemming from the improper handling of the phar:// stream wrapper. This flaw allows for object injection attacks due to the lack of a protective mechanism to restrict the phar:// handler to actual .phar files. With a CVSS score of 9.8, it presents a severe risk as it can be exploited remotely with low attack complexity, potentially leading to complete compromise of confidentiality, integrity, and availability. Currently, there is no evidence of active exploitation, nor are there publicly available exploit modules or significant community discussion surrounding this vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 2.5.0, <= 3.9.2CPE matchmatch criteria | cpe:2.3:a:joomla:joomla\!:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.