---
id: CVE-2019-25762
title: >-
  Joomla! Component JoomProject 1.1.3.2 contains an information disclosure
  vulnerability that allows unauthenticated attackers to access sensitive user
  data by exploiting the projects endpoint
summary: >-
  Joomla! Component JoomProject 1.1.3.2 contains an information disclosure
  vulnerability that allows unauthenticated attackers to access sensitive user
  data by exploiting the projects endpoint. Attackers can send requests to
  index.php with…
severity: high
cvss: 7.5
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'
cwe:
  - CWE-359
vendor: joomboost
product: joomproject
affected:
  - joomproject = 1.1.3.2
published: '2026-06-19'
updated: '2026-08-21'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2019-25762'
references:
  - url: 'http://joomboost.com/'
    label: disclosure@vulncheck.com
  - url: >-
      https://extensions.joomla.org/extensions/extension/clients-a-communities/project-a-task-management/joomproject/
    label: disclosure@vulncheck.com
  - url: 'https://www.exploit-db.com/exploits/46121'
    label: disclosure@vulncheck.com
  - url: >-
      https://www.vulncheck.com/advisories/joomla-component-joomproject-information-disclosure
    label: disclosure@vulncheck.com
tags:
  - nvd
epss: 0.00632
epssPercentile: 0.48574
ingestedAt: '2026-08-22T13:32:35.326Z'
---

## Overview

Joomla! Component JoomProject 1.1.3.2 contains an information disclosure vulnerability that allows unauthenticated attackers to access sensitive user data by exploiting the projects endpoint. Attackers can send requests to index.php with option=com_jpprojects&view=projects&tmpl=component&format=json parameters to retrieve user IDs, names, and email addresses in JSON format.

## Affected

- `joomproject = 1.1.3.2`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
