Vulnerability Bulletins

[20170408] - Core - Information Disclosure

   
Affected software Joomla
 
Project: Joomla! SubProject: CMS Severity: Low Versions: 3.4.0 through 3.6.5 Exploit type: Information Disclosure Reported Date: 2016-Feb-06 Fixed Date: 2017-April-25 CVE Number: CVE-2017-8057 Description Multiple files caused full path disclosures on systems with enabled error reporting. Affected Installs Joomla! CMS versions 3.4.0 through 3.6.5 Solution Upgrade to version 3.7.0 Contact The JSST at the Joomla! Security Centre. Reported By: Sim of tencent security

More info:

http://feeds.joomla.org/~r/JoomlaSecurityNews/~3/mbhX_2RP00g/690-20170408-core-information-disclosure.html