Description
Joomla! before 1.5.15 allows remote attackers to read an extension's XML file, and thereby obtain the extension's version number, via a direct request.
Remediation
References
Related Vulnerabilities
Artifactory Missing Authorization Vulnerability (CVE-2019-10322)
MediaWiki Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2020-29004)
WordPress Plugin Bulk Datetime Change Security Bypass (1.11)
IBM WebSEAL Incorrect Authorization Vulnerability (CVE-2023-38368)
Plone CMS URL Redirection to Untrusted Site ('Open Redirect') Vulnerability (CVE-2017-1000484)