QID 730735

Date Published: 2023-02-22

QID 730735: Joomla Webservice Endpoints Improper Access Control Vulnerability

Joomla! is a free and open-source content management system for publishing web content on websites.

An improper access check allows unauthorized access to webservice endpoints.

Affected Versions:

Joomla! versions 4.0.0 to 4.2.7
QID Detection Logic: (Unauthenticated)
This QID sends a HTTP GET request to access vulnerable webservice endpoint and based on the response confirms if the target application is vulnerable.

Successful exploitation could allow a remote attacker to access sensitive information regarding the target application.

  • CVSS V3 rated as Medium - 5.3 severity.
  • CVSS V2 rated as Medium - 5 severity.
  • Solution
    Customers are advised to install latest Joomla version 4.2.8. For more information regarding this vulnerability please visit Joomla! Security Advisory.

    CVEs related to QID 730735

    Software Advisories
    Advisory ID Software Component Link
    Joomla Security Advisory URL Logo developer.joomla.org/security-centre/894-20230201-core-improper-access-check-in-webservice-endpoints.html