CVE-2017-18345: Joomanager Project Joomanager
Critical severity, CVSS 9.8. EPSS: 3% chance of exploitation in the next 30 days.
The Joomanager component through 2.0.0 for Joomla! has an arbitrary file download issue, resulting in exposing the credentials of the database via an index.php?option=com_joomanager&controller=details&task=download&path=configuration.php request.
Affected products
- Joomanager Project Joomanager: up to and including 2.0.0
Published 2018-08-26. Last modified 2026-06-17.