ZeroHour

CVE-2023-23752

KEVlarge

Improper Access Control in Joomla! Webservice Endpoints (CVE-2023-23752)

CISA: Joomla! Improper Access Control Vulnerability

CVSS 3.1
5.3 medium
EPSS
100%p100
Published
()
KEV added
AI analysis

Joomla! contains an improper access control flaw (CWE-284) in its webservice (REST API) endpoints: the API fails to enforce authentication, so unauthenticated remote attackers can access protected endpoints directly. It is triggered simply by sending crafted HTTP requests to the affected /api webservice routes without credentials, for example the route that exposes site application configuration. A successful request leaks sensitive configuration data, most notably database connection credentials, which attackers can use for further intrusion into the site's database and hosting environment. Any site running the affected Joomla! 4.x releases whose webservice endpoints are reachable is affected. Exploitation is confirmed in the wild — the flaw was added to CISA's KEV catalog on 2024-01-08 and carries a 99.8% EPSS probability of exploitation within 30 days — though no public proof-of-concept is known and ransomware use has not been confirmed.

What to do: Upgrade all Joomla! 4.x sites to 4.2.8 or later per the vendor's instructions, satisfying the CISA KEV required action. If upgrading is not immediately possible, restrict or block unauthenticated access to the /api/index.php webservice routes at the web server or WAF, treat any exposed database credentials as compromised (rotate them), and review logs for unauthenticated requests to /api endpoints. Organizations that cannot mitigate should discontinue use of the affected product per the CISA required action.

Affected
Joomla!Joomla! 4.0.0 through 4.2.7 (webservice endpoints introduced in the 4.x branch); fixed in Joomla! 4.2.8
Estimated exposure
large≈300,000–500,000 Joomla! 4.x sites (hundreds of thousands), of which tens of thousands have the /api webservice routes directly exposed — Joomla! powers on the order of 1–2 million websites and only a minority ran the 4.x branch that introduced the affected webservice endpoints at the time of disclosure, while public internet scans have shown tens of thousands of exposed…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

An issue was discovered in Joomla! 4.0.0 through 4.2.7. An improper access check allows unauthorized access to webservice endpoints.

CISA Known Exploited Vulnerability
Affected
Joomla! Joomla!
Required action
Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
Due date
Ransomware use
Unknown
Vendors
joomla
Products
joomla\!
Ecosystems
Joomla
Weakness
CWE-284
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

In the news