ZeroHour
The Hacker Newspublished ()ingested @TheHackersNews

Joomla Joomla! Two Critical Flaws Discovered — Update to Protect Your Site

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2016-8869
+1 in the same advisory: …8870
The register method in the UsersModelRegistration class in controllers/user.php in the Users component in Joomla! before 3.6.4 allows remote attackers to gain p

The register method in the UsersModelRegistration class in controllers/user.php in the Users component in Joomla! before 3.6.4 allows remote attackers to gain privileges by leveraging incorrect use of unfiltered data when registering on a site.

NVD description · AI analysis pending
9.8
group max
97% PoC ×2
  • joomla joomla\!
Full article212 words · extracted from thehackernews.com · click to collapse

The Hacker NewsOct 25, 2016

Joomla – the world's second popular open source Content Management System (CMS) software packages, has just released the latest version of its CMS, which includes patches for two critical security vulnerabilities and a bug fix.

The two critical flaws, both exist in the Joomla Core functionalities, include Account Creation Vulnerability (CVE-2016-8870) and Elevated Privileges flaw (CVE-2016-8869) that, if unpatched, could put millions of websites that run on Joomla at risk.

The account creation bug could allow any user to register on a website, even if the registration process has been disabled, while the elevated privileges flaw could enable users to perform advanced functions on a registered site that ordinary users are not authorized to do.

Both the critical vulnerabilities affect Joomla version 3.4.4 through 3.6.3. The update also includes a bug fix for Two-Factor Authentication.

Millions of websites used in e-commerce and other sensitive industries used Joomla, including big brand services such as McDonalds, Linux.com, General Electric, and major news sites.

So, Joomla administrators are recommended to quickly update their websites to the updated version 3.6.4 of the CMS immediately.

Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post.

Text extracted automatically; images, tables and formatting may be missing. Original: https://thehackernews.com/2016/10/joomla-security-update.html