CVE-2017-18345: Joomanager Project Joomanager

Critical severity, CVSS 9.8. EPSS: 3% chance of exploitation in the next 30 days.

The Joomanager component through 2.0.0 for Joomla! has an arbitrary file download issue, resulting in exposing the credentials of the database via an index.php?option=com_joomanager&controller=details&task=download&path=configuration.php request.

Affected products

Published 2018-08-26. Last modified 2026-06-17.