Description
An issue was discovered in Joomla! 2.5.0 through 3.9.22. The globlal configuration page does not remove secrets from the HTML output, disclosing the current values.
Remediation
References
Related Vulnerabilities
WordPress Plugin eventON Multiple Cross-Site Scripting Vulnerabilities (2.6.11)
WordPress Plugin Mapwiz SQL Injection (1.0.1)
ReviveAdserver Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2016-9456)
LiteSpeed Web Server Out-of-bounds Read Vulnerability (CVE-2004-0112)
WordPress Plugin Accept Stripe Donation-AidWP Security Bypass (2.8)