vendor:
Joomla Captcha Plugin
by:
dun
N/A
CVSS
MEDIUM
Local File Disclosure
22
CWE
Product Name: Joomla Captcha Plugin
Affected Version From: Up to version 4.5.1
Affected Version To: Up to version 4.5.1
Patch Exists: YES
Related CWE: Not provided
CPE: Not provided
Platforms Tested: Not provided
Not provided
Joomla Captcha Plugin <= 4.5.1 Local File Disclosure Vulnerability
The Joomla Captcha Plugin <= 4.5.1 is vulnerable to a local file disclosure vulnerability. An attacker can exploit this vulnerability by sending a specially crafted request to the 'playcode.php' file. By manipulating the 'lng' parameter in the request, an attacker can disclose the contents of arbitrary files on the server, such as the '/etc/passwd' file.
Mitigation:
Update to the latest version of the Joomla Captcha Plugin.