QID 154109

Date Published: 2022-05-20

QID 154109: Joomla! Core Improper Authentication Vulnerability (CVE-2022-23795)

Joomla! is a free and open-source content management system for publishing web content on websites.

Affected versions of this package are vulnerable to improper authentication. A user row was not bound to a specific authentication mechanism which could under very special circumstances allow an account takeover.

Affected Versions:
Joomla 3.0.0 to 3.10.6
Joomla 4.0.0 to 4.1.0

QID Detection Logic:(Unauthenticated)
This QID checks for vulnerable version of Joomla installed on the target.

Successful exploitation of this vulnerability can allow account takeover.

  • CVSS V3 rated as Critical - 9.8 severity.
  • CVSS V2 rated as High - 6.8 severity.
  • Solution
    Customers are advised to install latest Joomla version.
    For more information visit Joomla security advisory [20220303].
    Vendor References

    CVEs related to QID 154109

    Software Advisories
    Advisory ID Software Component Link
    [20220303] URL Logo developer.joomla.org/security-centre/872-20220303-core-user-row-are-not-bound-to-a-authentication-mechanism.html