Moderate severityNVD Advisory· Published Mar 30, 2022· Updated Feb 25, 2026
[20220302] - Core - Path Disclosure within filesystem error messages
CVE-2022-23794
Description
An issue was discovered in Joomla! 3.0.0 through 3.10.6 & 4.0.0 through 4.1.0. Uploading a file name of an excess length causes the error. This error brings up the screen with the path of the source code of the web application.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
joomla/filesystemPackagist | < 1.6.2 | 1.6.2 |
joomla/filesystemPackagist | >= 2.0.0, < 2.0.1 | 2.0.1 |
Affected products
1- Range: 3.0.0-3.10.6 & 4.0.0-4.1.0
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
4- developer.joomla.org/security-centre/871-20220302-core-path-disclosure-within-filesystem-error-messages.htmlghsax_refsource_MISCvendor-advisoryWEB
- github.com/advisories/GHSA-rc8q-45v8-x6xcghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2022-23794ghsaADVISORY
- github.com/FriendsOfPHP/security-advisories/blob/master/joomla/filesystem/CVE-2022-23794.yamlghsaWEB
News mentions
0No linked articles in our index yet.