THREATOPS
THREAT OPSThreat News › [NVD] CVE-2019-25760 (MEDIUM 6.2) — Joomla! Component Easy Shop 1.2.3 contains a local file inclusion vulnerability that allows unauthenticated attackers to read arbitrary files by supplying base64-encoded file paths. Attackers can send GET requests to index.php with the option parameter set to com_easyshop, task s

[NVD] CVE-2019-25760 (MEDIUM 6.2) — Joomla! Component Easy Shop 1.2.3 contains a local file inclusion vulnerability that allows unauthenticated attackers to read arbitrary files by supplying base64-encoded file paths. Attackers can send GET requests to index.php with the option parameter set to com_easyshop, task s

lownvdPublished 2026-06-19

CVE-2019-25760 CVSS: 6.2 MEDIUM Published: 2026-06-19T18:16:18.890

Joomla! Component Easy Shop 1.2.3 contains a local file inclusion vulnerability that allows unauthenticated attackers to read arbitrary files by supplying base64-encoded file paths. Attackers can send GET requests to index.php with the option parameter set to com_easyshop, task set to ajax.loadImage, and a base64-encoded file path

Indicators of compromise

Original source: https://nvd.nist.gov/vuln/detail/CVE-2019-25760