THREAT OPS › Threat News › [NVD] CVE-2019-25760 (MEDIUM 6.2) — Joomla! Component Easy Shop 1.2.3 contains a local file inclusion vulnerability that allows unauthenticated attackers to read arbitrary files by supplying base64-encoded file paths. Attackers can send GET requests to index.php with the option parameter set to com_easyshop, task s
[NVD] CVE-2019-25760 (MEDIUM 6.2) — Joomla! Component Easy Shop 1.2.3 contains a local file inclusion vulnerability that allows unauthenticated attackers to read arbitrary files by supplying base64-encoded file paths. Attackers can send GET requests to index.php with the option parameter set to com_easyshop, task s
CVE-2019-25760 CVSS: 6.2 MEDIUM Published: 2026-06-19T18:16:18.890
Joomla! Component Easy Shop 1.2.3 contains a local file inclusion vulnerability that allows unauthenticated attackers to read arbitrary files by supplying base64-encoded file paths. Attackers can send GET requests to index.php with the option parameter set to com_easyshop, task set to ajax.loadImage, and a base64-encoded file path
Indicators of compromise
- CVE-2019-25760cve
Original source: https://nvd.nist.gov/vuln/detail/CVE-2019-25760