QID 730635
Date Published: 2022-11-09
QID 730635: Joomla Multiple Security Vulnerabilities (20220303 and 20220306)
Joomla is a free and open-source content management system written in PHP. It uses object oriented programming techniques and is built on a model-view-controller web application framework. It includes features such as page caching, RSS feeds, printable versions of pages, news flashes, blogs, polls, search, and support for language internationalization.
CVE-2022-23795: A user row was not bound to a specific authentication mechanism which could under very special circumstances allow an account takeover.
CVE-2022-23798: Inadequate validation of URLs could result into an invalid check whether an redirect URL is internal or not.
Affected Version:
Joomla! CMS versions from 2.5.0 prior to 3.10.7
Joomla! CMS versions from 4.0.0 prior to 4.1.1
Fixed Version:
Upgrade to version 3.10.7 and 4.1.1
QID Detection Logic(Unauthenticated):
QID checks for the Vulnerable version of Joomla.
Successful exploitation of this vulnerability may allow attackers either to trick a user into visiting a specially crafted link which would redirect them to an arbitrary malicious external URL or could under very special circumstances allow an account takeover.
- 20220303 and 20220306 -
developer.joomla.org/security-centre.html
CVEs related to QID 730635
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| 20220303 and 20220306 |
|