← Vulnerability feed

Vulnerability record · CVE-2015-4074 · published 20 September 2017

CVE-2015-4074: Joomla Helpdesk Pro plugin path traversal in attachment download

Helpdesk Pro Project · Helpdesk Pro

The Helpdesk Pro plugin before 1.4.0 for Joomla! contains a directory traversal flaw in the ticket.download_attachment task, where the filename parameter accepts .. sequences. An unauthenticated remote attacker can use this to read files outside the intended attachment directory, exposing configuration and credential material on the web server.

7.5 CVSS 3.0 High EPSS 57% · top 1.0% CWE-22 · Path traversal
7.5CVSS 3.0 base score, v2 5.0
57%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
8References, 8 tagged exploit
17 Jun 2026Last modified by NVD

Description

Directory traversal vulnerability in the Helpdesk Pro plugin before 1.4.0 for Joomla! allows remote attackers to read arbitrary files via a .. (dot dot) in the filename parameter in a ticket.download_attachment task.

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 19 September 2026. Confidence: high.

high priorityUnauthenticated remote file disclosure with public exploit code and a very high EPSS score, though limited to confidentiality impact and requiring the vulnerable plugin to be installed.

What it is

The Helpdesk Pro plugin before 1.4.0 for Joomla! contains a directory traversal flaw in the ticket.download_attachment task, where the filename parameter accepts .. sequences. An unauthenticated remote attacker can use this to read files outside the intended attachment directory, exposing configuration and credential material on the web server.

Impact

An attacker gains read access to arbitrary files on the host, including Joomla configuration files that hold database credentials, which can lead to further compromise. There is no write or code execution impact from this flaw alone.

Attack surface

Reached over the network through the Joomla component's ticket.download_attachment task with a crafted filename parameter; the CVSS vector shows no privileges and no user interaction required. No authentication is needed.

Exploitation

Public exploit code exists, referenced by Exploit-DB, Packet Storm, Full Disclosure and SecurityFocus, and EPSS is 0.5651 (99th percentile), indicating high likelihood of attempted exploitation. It is not listed in CISA KEV.

What to do

  • Upgrade the Helpdesk Pro plugin to version 1.4.0 or later, which fixes the traversal.
  • If upgrade is not possible, disable or remove the plugin until it can be patched.
  • Restrict filesystem permissions so the web server user cannot read sensitive files such as configuration.php.
  • Deploy WAF rules that block traversal sequences in the filename parameter of ticket.download_attachment requests.

Detection

  • Search web logs for requests to ticket.download_attachment containing ../ or encoded traversal sequences in the filename parameter.
  • Alert on access to files outside the plugin's attachment directory, especially configuration.php or /etc/passwd.
  • Monitor for repeated 200 responses to attachment download requests with unusual filename values from the same source.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
http://packetstormsecurity.com/files/132766/Joomla-Helpdesk-Pro-XSS-File-Disclosure-SQL-Injection.html ExploitThird Party AdvisoryVDB Entry
http://seclists.org/fulldisclosure/2015/Jul/102 ExploitMailing ListThird Party AdvisoryVDB Entry
http://www.securityfocus.com/bid/75971 ExploitThird Party AdvisoryVDB Entry
https://www.exploit-db.com/exploits/37666/ ExploitThird Party AdvisoryVDB Entry
http://packetstormsecurity.com/files/132766/Joomla-Helpdesk-Pro-XSS-File-Disclosure-SQL-Injection.html ExploitThird Party AdvisoryVDB Entry
http://seclists.org/fulldisclosure/2015/Jul/102 ExploitMailing ListThird Party AdvisoryVDB Entry
http://www.securityfocus.com/bid/75971 ExploitThird Party AdvisoryVDB Entry
https://www.exploit-db.com/exploits/37666/ ExploitThird Party AdvisoryVDB Entry

Track CVE-2015-4074 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2015-4073Helpdesk pro project helpdesk pro sql injection vulnerabilityMultiple SQL injection vulnerabilities in the Helpdesk Pro plugin before 1.4.0 for Joomla! allow remote attackers to execute arbitrary SQL commands v…EPSS 4.2%5.4CVE-2015-4072Helpdesk pro project helpdesk pro cross-site scripting vulnerabilityMultiple cross-site scripting (XSS) vulnerabilities in the Helpdesk Pro plugin before 1.4.0 for Joomla! allow remote attackers to inject arbitrary we…EPSS 2.9%5.3CVE-2015-4071Helpdesk pro project helpdesk pro information exposure vulnerabilityThe Helpdesk Pro Plugin before 1.4.0 for Joomla! allows remote attackers to read the support tickets of arbitrary users via obtaining the target tick…EPSS 9.6%9.8CVE-2026-93616Checkpoint multi-domain security management path traversal vulnerabilityA directory traversal and file upload vulnerability allows an unauthenticated attacker to upload and execute arbitrary scripts on Check Point Managem…KEVEPSS 20%10.0CVE-2026-85706GitLab CE/EE repository commits API path traversal allows unauthenticated file readGitLab CE/EE contains improper path confinement and missing authentication enforcement in the repository commits API, allowing an unauthenticated use…KEVEPSS 91%analysed5.3CVE-2026-66384JFrog Artifactory path traversal in Docker cache pathAn authenticated user can write data outside the intended Docker cache path under specific remote-repository conditions in JFrog Artifactory. The fla…KEVEPSS 0.66%analysed9.8CVE-2026-59310VMware vCenter Syslog server path traversal leads to RCEVMware vCenter's Syslog server is affected by a directory traversal flaw (CWE-22) that allows a remote, unauthenticated attacker to execute arbitrary…KEVEPSS 2.6%analysed10.0CVE-2026-48282Adobe ColdFusion path traversal leads to remote code executionColdFusion versions 2025.9, 2023.20 and earlier contain a path traversal flaw (CWE-22) that allows an unauthenticated remote attacker to reach files …KEVEPSS 42%analysed

Source: NIST National Vulnerability Database (record CVE-2015-4074), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.