QID 730093

Date Published: 2021-05-31

QID 730093: Joomla Multiple Security Vulnerabilities (20210501, 20210502, 20210503)

Joomla is a free and open-source content management system written in PHP. It uses object oriented programming techniques and is built on a model-view-controller web application framework. It includes features such as page caching, RSS feeds, printable versions of pages, news flashes, blogs, polls, search, and support for language internationalization.

Affected Version:
Joomla! CMS versions from 3.0.0 to 3.9.26

Fixed Version:
Upgrade to version 3.9.27

QID Detection Logic(Unauthenticated):
QID checks for the Vulnerable version of Joomla.

Successful exploitation could affects on integrity, confidentiality, availability.

  • CVSS V3 rated as High - 6.3 severity.
  • CVSS V2 rated as High - 7.5 severity.
  • Solution
    The vendor has released a patch in Joomla to remediate this vulnerability.

    CVEs related to QID 730093

    Software Advisories
    Advisory ID Software Component Link
    20210501 URL Logo developer.joomla.org/security-centre/852-20210501-core-adding-html-to-the-executable-block-list-of-mediahelper-canupload.html
    20210502 URL Logo developer.joomla.org/security-centre/853-20210502-core-csrf-in-ajax-reordering-endpoint.html
    20210503 URL Logo developer.joomla.org/security-centre/854-20210503-core-csrf-in-data-download-endpoints.html