Vulnerability record · CVE-2015-4074 · published 20 September 2017
CVE-2015-4074: Joomla Helpdesk Pro plugin path traversal in attachment download
Helpdesk Pro Project · Helpdesk Pro
The Helpdesk Pro plugin before 1.4.0 for Joomla! contains a directory traversal flaw in the ticket.download_attachment task, where the filename parameter accepts .. sequences. An unauthenticated remote attacker can use this to read files outside the intended attachment directory, exposing configuration and credential material on the web server.
Description
Directory traversal vulnerability in the Helpdesk Pro plugin before 1.4.0 for Joomla! allows remote attackers to read arbitrary files via a .. (dot dot) in the filename parameter in a ticket.download_attachment task.
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Automated analysis
high priorityUnauthenticated remote file disclosure with public exploit code and a very high EPSS score, though limited to confidentiality impact and requiring the vulnerable plugin to be installed.
What it is
The Helpdesk Pro plugin before 1.4.0 for Joomla! contains a directory traversal flaw in the ticket.download_attachment task, where the filename parameter accepts .. sequences. An unauthenticated remote attacker can use this to read files outside the intended attachment directory, exposing configuration and credential material on the web server.
Impact
An attacker gains read access to arbitrary files on the host, including Joomla configuration files that hold database credentials, which can lead to further compromise. There is no write or code execution impact from this flaw alone.
Attack surface
Reached over the network through the Joomla component's ticket.download_attachment task with a crafted filename parameter; the CVSS vector shows no privileges and no user interaction required. No authentication is needed.
Exploitation
Public exploit code exists, referenced by Exploit-DB, Packet Storm, Full Disclosure and SecurityFocus, and EPSS is 0.5651 (99th percentile), indicating high likelihood of attempted exploitation. It is not listed in CISA KEV.
What to do
- Upgrade the Helpdesk Pro plugin to version 1.4.0 or later, which fixes the traversal.
- If upgrade is not possible, disable or remove the plugin until it can be patched.
- Restrict filesystem permissions so the web server user cannot read sensitive files such as configuration.php.
- Deploy WAF rules that block traversal sequences in the filename parameter of ticket.download_attachment requests.
Detection
- Search web logs for requests to ticket.download_attachment containing ../ or encoded traversal sequences in the filename parameter.
- Alert on access to files outside the plugin's attachment directory, especially configuration.php or /etc/passwd.
- Monitor for repeated 200 responses to attachment download requests with unusual filename values from the same source.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| http://packetstormsecurity.com/files/132766/Joomla-Helpdesk-Pro-XSS-File-Disclosure-SQL-Injection.html | ExploitThird Party AdvisoryVDB Entry |
| http://seclists.org/fulldisclosure/2015/Jul/102 | ExploitMailing ListThird Party AdvisoryVDB Entry |
| http://www.securityfocus.com/bid/75971 | ExploitThird Party AdvisoryVDB Entry |
| https://www.exploit-db.com/exploits/37666/ | ExploitThird Party AdvisoryVDB Entry |
| http://packetstormsecurity.com/files/132766/Joomla-Helpdesk-Pro-XSS-File-Disclosure-SQL-Injection.html | ExploitThird Party AdvisoryVDB Entry |
| http://seclists.org/fulldisclosure/2015/Jul/102 | ExploitMailing ListThird Party AdvisoryVDB Entry |
| http://www.securityfocus.com/bid/75971 | ExploitThird Party AdvisoryVDB Entry |
| https://www.exploit-db.com/exploits/37666/ | ExploitThird Party AdvisoryVDB Entry |
Track CVE-2015-4074 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2015-4074), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.