Joomla! Component JoomProject 1.1.3.2 contains an information disclosure vulnerability that allows unauthenticated attackers to access sensitive user data by exploiting the projects endpoint. Attackers can send requests to index.php with option=com_jpprojects&view=projects&tmpl=component&format=json parameters to retrieve user IDs, names, and email addresses in JSON format.
References
| Link | Resource |
|---|---|
| http://joomboost.com/ | Product |
| https://extensions.joomla.org/extensions/extension/clients-a-communities/project-a-task-management/joomproject/ | Product |
| https://www.exploit-db.com/exploits/46121 | Exploit VDB Entry |
| https://www.vulncheck.com/advisories/joomla-component-joomproject-information-disclosure | Third Party Advisory |
Configurations
History
No history.
Information
Published : 2026-06-19 18:16
Updated : 2026-08-21 14:40
NVD link : CVE-2019-25762
Mitre link : CVE-2019-25762
CVE.ORG link : CVE-2019-25762
JSON object : View
Products Affected
joomboost
- joomproject
CWE
CWE-359
Exposure of Private Personal Information to an Unauthorized Actor
