{ "id": "CVE-2020-5182", "sourceIdentifier": "cve@mitre.org", "published": "2020-02-03T17:15:15.813", "lastModified": "2021-07-21T11:39:23.747", "vulnStatus": "Analyzed", "descriptions": [ { "lang": "en", "value": "The J-BusinessDirectory extension before 5.2.9 for Joomla! allows Reverse Tabnabbing. In some configurations, the link to the business website can be entered by any user. If it doesn't contain rel=\"noopener\" (or similar attributes such as noreferrer), the tabnabbing may occur. To reproduce the bug, create a business with a website link that contains JavaScript to exploit the window.opener property (for example, by setting window.opener.location)." }, { "lang": "es", "value": "La extensi\u00f3n J-BusinessDirectory versiones anteriores a 5.2.9 para Joomla!, permite revertir un ataque tipo tabnabbing. En algunas configuraciones, el enlace al sitio web de la empresa puede ser ingresado por cualquier usuario. Si no contiene rel=\"noopener\" (o atributos similares como noreferrer), puede presentarse el ataque tipo tabnabbing. Para reproducir el bug, cree un negocio con un enlace al sitio web que contenga JavaScript para explotar la propiedad window.opener (por ejemplo, configurando window.opener.location)." } ], "metrics": { "cvssMetricV31": [ { "source": "nvd@nist.gov", "type": "Primary", "cvssData": { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N", "attackVector": "NETWORK", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "REQUIRED", "scope": "UNCHANGED", "confidentialityImpact": "HIGH", "integrityImpact": "NONE", "availabilityImpact": "NONE", "baseScore": 6.5, "baseSeverity": "MEDIUM" }, "exploitabilityScore": 2.8, "impactScore": 3.6 } ], "cvssMetricV2": [ { "source": "nvd@nist.gov", "type": "Primary", "cvssData": { "version": "2.0", "vectorString": "AV:N/AC:M/Au:N/C:P/I:N/A:N", "accessVector": "NETWORK", "accessComplexity": "MEDIUM", "authentication": "NONE", "confidentialityImpact": "PARTIAL", "integrityImpact": "NONE", "availabilityImpact": "NONE", "baseScore": 4.3 }, "baseSeverity": "MEDIUM", "exploitabilityScore": 8.6, "impactScore": 2.9, "acInsufInfo": false, "obtainAllPrivilege": false, "obtainUserPrivilege": false, "obtainOtherPrivilege": false, "userInteractionRequired": true } ] }, "weaknesses": [ { "source": "nvd@nist.gov", "type": "Primary", "description": [ { "lang": "en", "value": "CWE-269" } ] } ], "configurations": [ { "nodes": [ { "operator": "OR", "negate": false, "cpeMatch": [ { "vulnerable": true, "criteria": "cpe:2.3:a:cmsjunkie:j-businessdirectory:*:*:*:*:*:joomla\\!:*:*", "versionEndExcluding": "5.2.9", "matchCriteriaId": "7284D5E4-ACDE-441A-AFCB-C76398BB6589" } ] } ] } ], "references": [ { "url": "https://www.cmsjunkie.com/blog/joomla_business_directory_5-2-9_release/", "source": "cve@mitre.org", "tags": [ "Release Notes", "Vendor Advisory" ] } ] }