QID 154131

Date Published: 2023-02-06

QID 154131: Joomla! Core Incorrect Access Control Vulnerability (CVE-2023-23751)

Joomla! is a free and open-source content management system for publishing web content on websites.

In the installed version of Joomla, a missing ACL check allows non super-admin users to access com_actionlogs.

Affected Versions:
Joomla! CMS versions 4.0.0 to 4.2.6

QID Detection Logic:(Unauthenticated)
This QID checks for vulnerable version of Joomla installed on the target.

Successful exploitation would lead attackers to access com_actionlogs, which can help the attacker carry out further attacks and obtain sensitive information.

  • CVSS V3 rated as Medium - 4.3 severity.
  • CVSS V2 rated as Medium - 5 severity.
  • Solution
    Customers are advised to install latest Joomla version.
    For more information visit Joomla security advisory [20230102].

    CVEs related to QID 154131

    Software Advisories
    Advisory ID Software Component Link
    20230102 URL Logo developer.joomla.org/security-centre/891-20230102-core-missing-acl-checks-for-com-actionlogs.html