QID 730735
Date Published: 2023-02-22
QID 730735: Joomla Webservice Endpoints Improper Access Control Vulnerability
Joomla! is a free and open-source content management system for publishing web content on websites.
An improper access check allows unauthorized access to webservice endpoints.
Affected Versions:
Joomla! versions 4.0.0 to 4.2.7
QID Detection Logic: (Unauthenticated)
This QID sends a HTTP GET request to access vulnerable webservice endpoint and based on the response confirms if the target application is vulnerable.
Successful exploitation could allow a remote attacker to access sensitive information regarding the target application.
Solution
Customers are advised to install latest Joomla version 4.2.8. For more information regarding this vulnerability please visit Joomla! Security Advisory.
Vendor References
- Joomla Security Advisory -
developer.joomla.org/security-centre/894-20230201-core-improper-access-check-in-webservice-endpoints.html
CVEs related to QID 730735
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| Joomla Security Advisory |
|