QID 11999
Date Published: 2021-03-30
QID 11999: Joomla Core Multiple Vulnerabilities(20210305, 20210302, 20210301)
Joomla is a free and open-source content management system written in PHP. It uses object oriented programming techniques and is built on a model-view-controller web application framework. It includes features such as page caching, RSS feeds, printable versions of pages, news flashes, blogs, polls, search, and support for language internationalization.
Affected Version:
Joomla! CMS versions 3.2.0 - 3.9.24
Fixed Version:
Upgrade to version 3.9.25
QID Detection Logic(Unauthenticated):
QID checks for the Vulnerable version of Joomla.
Successful exploitation could impact integrity, confidentiality, availability.
Solution
The vendor has released a patch in Joomla to remediate this vulnerability.
Vendor References
- 20210301 -
developer.joomla.org/security-centre/841-20210301-core-insecure-randomness-within-2fa-secret-generation.html - 20210302 -
developer.joomla.org/security-centre/842-20210302-core-potential-insecure-fofencryptrandval.html - 20210305 -
developer.joomla.org/security-centre/845-20210305-core-input-validation-within-the-template-manager.html
CVEs related to QID 11999
Software Advisories