CVE-2023-23752
KEVlargeImproper Access Control in Joomla! Webservice Endpoints (CVE-2023-23752)
CISA: Joomla! Improper Access Control Vulnerability
Joomla! contains an improper access control flaw (CWE-284) in its webservice (REST API) endpoints: the API fails to enforce authentication, so unauthenticated remote attackers can access protected endpoints directly. It is triggered simply by sending crafted HTTP requests to the affected /api webservice routes without credentials, for example the route that exposes site application configuration. A successful request leaks sensitive configuration data, most notably database connection credentials, which attackers can use for further intrusion into the site's database and hosting environment. Any site running the affected Joomla! 4.x releases whose webservice endpoints are reachable is affected. Exploitation is confirmed in the wild — the flaw was added to CISA's KEV catalog on 2024-01-08 and carries a 99.8% EPSS probability of exploitation within 30 days — though no public proof-of-concept is known and ransomware use has not been confirmed.
What to do: Upgrade all Joomla! 4.x sites to 4.2.8 or later per the vendor's instructions, satisfying the CISA KEV required action. If upgrading is not immediately possible, restrict or block unauthenticated access to the /api/index.php webservice routes at the web server or WAF, treat any exposed database credentials as compromised (rotate them), and review logs for unauthenticated requests to /api endpoints. Organizations that cannot mitigate should discontinue use of the affected product per the CISA required action.
| Joomla! | Joomla! 4.0.0 through 4.2.7 (webservice endpoints introduced in the 4.x branch); fixed in Joomla! 4.2.8 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
An issue was discovered in Joomla! 4.0.0 through 4.2.7. An improper access check allows unauthorized access to webservice endpoints.
- Affected
- Joomla! Joomla!
- Required action
- Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
- Due date
- Ransomware use
- Unknown
- Vendors
- joomla
- Products
- joomla\!
- Ecosystems
- Joomla
- Weakness
- CWE-284
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N