QID 731036

Date Published: 2023-12-19

QID 731036: Joomla Information Disclosure Vulnerability (20231101)

Joomla is a free and open-source content management system written in PHP. It uses object oriented programming techniques and is built on a model-view-controller web application framework. It includes features such as page caching, RSS feeds, printable versions of pages, news flashes, blogs, polls, search, and support for language internationalization.

CVE-2023-23755: Joomla versions 4.2.0 through 4.3.1 is vulnerable to brute force attacks against MFA methods.
CVE-2023-23754: Joomla versions 4.2.0 through 4.3.1 is vulnerable open redirect and XSS issue within the new mfa selection screen.

Affected Version:
Joomla! CMS versions from 1.6.0-4.4.0

Joomla! CMS version 5.0.0

Fixed Version:
Upgrade to version 3.10.14-elts, 4.4.1 or 5.0.1

QID Detection Logic(Unauthenticated):
QID checks for the Vulnerable version of Joomla.

Successful exploit may lead to information disclosure

  • CVSS V3 rated as High - 7.5 severity.
  • CVSS V2 rated as Medium - 5 severity.
  • Solution
    The vendor has released a patch in 3.10.14-elts, 4.4.1 or 5.0.1 to remediate this vulnerability.

    CVEs related to QID 731036

    Software Advisories
    Advisory ID Software Component Link
    20231101 URL Logo developer.joomla.org/security-centre/919-20231101-core-exposure-of-environment-variables.html