QID 154142

Date Published: 2023-06-19

QID 154142: Joomla! Core Multiple Vulnerabilities (CVE-2023-23755, CVE-2023-23754)

Joomla! is a free and open-source content management system for publishing web content on websites.

Affected versions of Joomla Core have multiple vulnerabilities:

CVE-2023-23755 : The lack of rate limiting allowed brute force attacks against MFA methods.
CVE-2023-23754 : Lack of input validation caused an open redirect and XSS issue within the new mfa selection screen.

Affected Versions:
Joomla! CMS versions 4.2.0 - 4.3.1

QID Detection Logic:(Unauthenticated)
This QID checks for vulnerable version of Joomla installed on the target.

Successful exploitation of these vulnerabilities could allow an unauthenticated attacker to compromise Joomla Server.

  • CVSS V3 rated as High - 7.5 severity.
  • CVSS V2 rated as Medium - 5 severity.
  • Solution
    Customers are advised to install latest Joomla version.
    For more information visit:
    Joomla security advisory [20230502].
    Joomla security advisory [20230501].

    CVEs related to QID 154142

    Software Advisories
    Advisory ID Software Component Link
    20230501 URL Logo developer.joomla.org/security-centre/899-20230501-core-open-redirects-and-xss-within-the-mfa-selection.html
    20230502 URL Logo developer.joomla.org/security-centre/900-20230502-core-bruteforce-prevention-within-the-mfa-screen.html