QID 730962

Date Published: 2023-10-31

QID 730962: Joomla Multiple Security Vulnerabilities (20230501,20230502)

Joomla is a free and open-source content management system written in PHP. It uses object oriented programming techniques and is built on a model-view-controller web application framework. It includes features such as page caching, RSS feeds, printable versions of pages, news flashes, blogs, polls, search, and support for language internationalization.

CVE-2023-23755: Joomla versions 4.2.0 through 4.3.1 is vulnerable to brute force attacks against MFA methods.
CVE-2023-23754: Joomla versions 4.2.0 through 4.3.1 is vulnerable open redirect and XSS issue within the new mfa selection screen.

Affected Version:
Joomla! CMS versions from 4.2.0 to 4.3.1

Fixed Version:
Upgrade to version 4.3.2

QID Detection Logic(Unauthenticated):
QID checks for the Vulnerable version of Joomla.

Successful exploitation of these vulnerabilities may allow an unauthenticated attacker to execute arbitrary JavaScript code on victim browser or brute force attacks.

  • CVSS V3 rated as High - 7.5 severity.
  • CVSS V2 rated as High - 6.4 severity.
  • Solution
    The vendor has released a patch in Joomla version 4.3.2 or later to remediate this vulnerability.

    CVEs related to QID 730962

    Software Advisories
    Advisory ID Software Component Link
    20230501 URL Logo developer.joomla.org/security-centre.html
    20230502 URL Logo developer.joomla.org/security-centre.html