peter bassill · operator
$ cve CVE-2013-1453 JSON

CVE-2013-1453 EXPLOIT

7.5
HIGH · CVSS 2.0 · EPSS 3.1% (pctl 88)

Patch early

A public exploit exists.

Description

plugins/system/highlight/highlight.php in Joomla! 3.0.x through 3.0.2 and 2.5.x through 2.5.8 allows attackers to unserialize arbitrary PHP objects to obtain sensitive information, delete arbitrary directories, conduct SQL injection attacks, and possibly have other impacts via the highlight parameter. Note: it was originally reported that this issue only allowed attackers to obtain sensitive information, but later analysis demonstrated that other attacks exist.

Scoring

CVSS7.5 (HIGH, v2.0)
VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
EPSS3.15% — more likely to be exploited than 88% of all CVEs
On CISA KEVno
Public exploityes
Published2013-02-13
Last modified2026-06-16

Affected (1)

VendorProduct
joomlajoomla\!

Public exploits

SourceTitleDate
exploit-dbJoomla! 3.0.2 - 'highlight.php' PHP Object Injection2013-02-27

References

→ the Explorer  ·  watch your stack  ·  NVD