Joomla! Core Login Authentication Bypass Vulnerability
BID:66121
Info
Joomla! Core Login Authentication Bypass Vulnerability
| Bugtraq ID: | 66121 |
| Class: | Design Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Mar 06 2014 12:00AM |
| Updated: | Mar 06 2014 12:00AM |
| Credit: | Stefania Gaianigo |
| Vulnerable: |
Joomla Joomla! 3.2.2 Joomla Joomla! 3.2.1 Joomla Joomla! 3.1.6 Joomla Joomla! 3.1.5 Joomla Joomla! 3.1.4 Joomla Joomla! 3.1.1 Joomla Joomla! 3.1 Joomla Joomla! 2.5.18 Joomla Joomla! 2.5.17 Joomla Joomla! 2.5.16 Joomla Joomla! 2.5.15 Joomla Joomla! 2.5.14 Joomla Joomla! 2.5.13 Joomla Joomla! 2.5.11 Joomla Joomla! 2.5.10 Joomla Joomla! 2.5.9 Joomla Joomla! 2.5.8 Joomla Joomla! 2.5.7 Joomla Joomla! 2.5.6 Joomla Joomla! 2.5.5 Joomla Joomla! 2.5.4 Joomla Joomla! 2.5.3 Joomla Joomla! 2.5.2 Joomla Joomla! 2.5.1 Joomla Joomla! 2.5 |
| Not Vulnerable: |
Joomla Joomla! 3.2.3 Joomla Joomla! 2.5.19 |
Discussion
Joomla! Core Login Authentication Bypass Vulnerability
Joomla! is prone to a authentication-bypass vulnerability.
Attackers can exploit this issue to bypass the authentication mechanism and log in to another user's account.
Joomla! 2.5.18, 3.2.2 and prior are vulnerable.
Joomla! is prone to a authentication-bypass vulnerability.
Attackers can exploit this issue to bypass the authentication mechanism and log in to another user's account.
Joomla! 2.5.18, 3.2.2 and prior are vulnerable.
Exploit / POC
Joomla! Core Login Authentication Bypass Vulnerability
Updates are available. Please see the references or vendor advisory for more information.
Updates are available. Please see the references or vendor advisory for more information.
Solution / Fix
Joomla! Core Login Authentication Bypass Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
Joomla! Core Login Authentication Bypass Vulnerability
References:
References:
- Joomla! Homepage (Joomla!)
- [20140304] - Core - Unauthorised Logins (Joomla)