QID 154142
Date Published: 2023-06-19
QID 154142: Joomla! Core Multiple Vulnerabilities (CVE-2023-23755, CVE-2023-23754)
Joomla! is a free and open-source content management system for publishing web content on websites.
Affected versions of Joomla Core have multiple vulnerabilities:
CVE-2023-23755 : The lack of rate limiting allowed brute force attacks against MFA methods.
CVE-2023-23754 : Lack of input validation caused an open redirect and XSS issue within the new mfa selection screen.
Affected Versions:
Joomla! CMS versions 4.2.0 - 4.3.1
QID Detection Logic:(Unauthenticated)
This QID checks for vulnerable version of Joomla installed on the target.
Successful exploitation of these vulnerabilities could allow an unauthenticated attacker to compromise Joomla Server.
Solution
Customers are advised to install latest Joomla version.
For more information visit:
Joomla security advisory [20230502].
Joomla security advisory [20230501].
For more information visit:
Joomla security advisory [20230502].
Joomla security advisory [20230501].
CVEs related to QID 154142
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| 20230501 |
|
||
| 20230502 |
|