ZeroHour

CVE-2016-8870

PoC
CVSS 3.0
8.1 high
EPSS
81%p100
Published
()
Modified
Description

The register method in the UsersModelRegistration class in controllers/user.php in the Users component in Joomla! before 3.6.4, when registration has been disabled, allows remote attackers to create user accounts by leveraging failure to check the Allow User Registration configuration setting.

Vendors
joomla
Products
joomla\!
Ecosystems
Joomla
Weakness
CWE-20
Vector
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news