
The Joomanager component through 2.0.0 for Joomla! has an Arbitrary File Download issue, resulting in exposing the Credentials of the DataBase.

Collecting databases in mass with plugin : COM_JOOMANAGER, From CMS: Joomla, Project developed in python 2.x, more information, access the youtube video.
CVE: 2017-18345 Risk: Security Risk High
0day.Today-ID: 29950 ExploitDB-id: 44252
0day db-id: 16348 CXSecurity-id: WLB-2018030054
CVSS v3.0 Severity and Metrics:
Base Score: 9.8 CRITICAL
alt tag
DEPENDENCES
BeautifulSoupThreadingurlparseurllib2argparserequests