QID 150651

Date Published: 2023-02-22

QID 150651: Joomla! Core Webservice Endpoints Improper access control Vulnerability (CVE-2023-23752)

Joomla! is a free and open-source content management system for publishing web content on websites.

An improper access check allows unauthorized access to webservice endpoints.

Affected Versions:
Joomla! versions 4.0.0 to 4.2.7

QID Detection Logic: (Unauthenticated)
This QID sends a HTTP GET request to access vulnerable webservice endpoint and based on the response confirms if the target application is vulnerable.

Successful exploitation could allow a remote attacker to access sensitive information regarding the target application.

  • CVSS V3 rated as Medium - 5.3 severity.
  • CVSS V2 rated as Medium - 5 severity.
  • Solution
    Customers are advised to install latest Joomla version 4.2.8. For more information regarding this vulnerability please visit Joomla! Security Advisory.

    CVEs related to QID 150651

    Software Advisories
    Advisory ID Software Component Link
    Joomla! Security Advisory URL Logo developer.joomla.org/security-centre/894-20230201-core-improper-access-check-in-webservice-endpoints.html