QID 730136

Date Published: 2021-07-12

QID 730136: Joomla Multiple Security Vulnerabilities (20210701, 20210702, 20210703, 20210704, 20210705)

Joomla is a free and open-source content management system written in PHP. It uses object oriented programming techniques and is built on a model-view-controller web application framework. It includes features such as page caching, RSS feeds, printable versions of pages, news flashes, blogs, polls, search, and support for language internationalization.

Multiple XSS, DOS, Incorrect Session Handling and Incorrect Access Control are detected in Joomla! CMS versions from 2.5.0 to 3.9.27

Affected Version:
Joomla! CMS versions from 2.5.0 to 3.9.27

Fixed Version:
Upgrade to version 3.9.28

NOTE:
CVE-2021-26039, CVE-2021-26035 only affect Joomla! CMS versions 3.0.0 - 3.9.27

QID Detection Logic(Unauthenticated):
QID checks for the Vulnerable version of Joomla.

Successful exploitation of these vulnerabilities may allow an attacker to steal sensitive data of the targeted user.

  • CVSS V3 rated as High - 7.5 severity.
  • CVSS V2 rated as Medium - 5 severity.
  • Solution
    The vendor has released a patch in Joomla to remediate this vulnerability.
    Vendor References
    Software Advisories
    Advisory ID Software Component Link
    20210701 URL Logo developer.joomla.org/security-centre.html
    20210702 URL Logo developer.joomla.org/security-centre.html
    20210703 URL Logo developer.joomla.org/security-centre.html
    20210704 URL Logo developer.joomla.org/security-centre.html
    20210705 URL Logo developer.joomla.org/security-centre.html