Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1110 CNY

100%

CVE-2023-40626 PoC — [20231101] - Core - Exposure of environment variables

Source
Associated Vulnerability
Title:[20231101] - Core - Exposure of environment variables (CVE-2023-40626)
Description:The language file parsing process could be manipulated to expose environment variables. Environment variables might contain sensible information.
Description
Plugin to fix security vulnerability CVE-2023-40626 in Joomla 3.10.12
Readme
THIS REPO IS OBSOLETE AND YOU SHOULD USE THIS ONE INSTEAD: https://github.com/TLWebdesign/Joomla-3-EOL-Security-Fixes


# Joomla-3.10.12 LanguageHelper.php Hotfix
 
This little plugin will help you update the LanguageHelper file with the security fix i backported from Joomla 4.4.1 More info on the vulnerability here: https://developer.joomla.org/security-centre/919-20231101-core-exposure-of-environment-variables.html

## Donate to the joomla project!
If this plugin saved you valuable time please consider donating something to the joomla project: https://community.joomla.org/donate. 
Especially agencies who will save tons of time when they have multiple websites still on J3. Any donation is much appreciated.

## Backup First!
Always try this fix first on a test environment because it could potentially break language files that were not following exact specification. Previously these language files would still work but in fixing the vulnerability the strictness of how these files are processed makes it that a language string can not have new lines in the content anymore.
File Snapshot

[4.0K] /data/pocs/ba55c489c5bc5ed642438830658606bb7a790269 ├── [ 22K] LanguageHelper.php ├── [ 718] languagehotfix.xml ├── [ 18K] LICENSE ├── [1.1K] README.md └── [2.0K] script.php 0 directories, 5 files
Shenlong Bot has cached this for you
Remarks
    1. It is advised to access via the original source first.
    2. Local POC snapshots are reserved for subscribers — if the original source is unavailable, the local mirror is part of the paid plan.
    3. Mirroring, verifying, and maintaining this POC archive takes ongoing effort, so local snapshots are a paid feature. Your subscription keeps the archive online — thank you for the support. View subscription plans →