QID 154152
Date Published: 2024-03-01
QID 154152: Joomla! Core Open Redirect Vulnerability (CVE-2024-21723)
Joomla! is a free and open-source content management system for publishing web content on websites.
In the installed version of Joomla, inadequate parsing of URLs could result into an open redirect.
Affected Versions:
Joomla! CMS versions 1.5.0 - 3.10.14-elts
Joomla! CMS versions 4.0.0 - 4.4.2
Joomla! CMS versions 5.0.0 - 5.0.2
QID Detection Logic:(Unauthenticated)
This QID checks for vulnerable version of Joomla installed on the target.
Successful exploitation could allow attackers to trick a user into visiting a specially crafted link which would redirect them to an arbitrary malicious external URL.
Solution
Customers are advised to install latest Joomla version.
For more information visit:
Joomla security advisory [20240202].
For more information visit:
Joomla security advisory [20240202].
Vendor References
CVEs related to QID 154152
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| 20240202 |
|