VYPR
Moderate severityNVD Advisory· Published Mar 30, 2022· Updated Feb 25, 2026

[20220302] - Core - Path Disclosure within filesystem error messages

CVE-2022-23794

Description

An issue was discovered in Joomla! 3.0.0 through 3.10.6 & 4.0.0 through 4.1.0. Uploading a file name of an excess length causes the error. This error brings up the screen with the path of the source code of the web application.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
joomla/filesystemPackagist
< 1.6.21.6.2
joomla/filesystemPackagist
>= 2.0.0, < 2.0.12.0.1

Affected products

1

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

4

News mentions

0

No linked articles in our index yet.