Description
An issue was discovered in Joomla! 3.0.0 through 3.9.23. The lack of ACL checks in the orderPosition endpoint of com_modules leak names of unpublished and/or inaccessible modules.
Remediation
References
Related Vulnerabilities
CKEditor Unrestricted Upload of File with Dangerous Type Vulnerability (CVE-2023-31541)
PostgreSQL Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2015-5288)
Chamilo Missing Authorization Vulnerability (CVE-2019-1000017)
Joomla Inadequate Encryption Strength Vulnerability (CVE-2021-23126)