Unrated severityNVD Advisory· Published Dec 28, 2020· Updated Feb 24, 2026
[20201102] - Core - Disclosure of secrets in Global Configuration page
CVE-2020-35611
Description
An issue was discovered in Joomla! 2.5.0 through 3.9.22. The globlal configuration page does not remove secrets from the HTML output, disclosing the current values.
Affected products
1- Range: 2.5.0-3.9.22
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1- developer.joomla.org/security-centre/829-20201102-core-disclosure-of-secrets-in-global-configuration-page.htmlmitrex_refsource_MISCvendor-advisory
News mentions
0No linked articles in our index yet.