QID 731192
Date Published: 2024-02-29
QID 731192: Joomla Session Misconfiguration Vulnerability (20240201)
Joomla is a free and open-source content management system written in PHP. It uses object oriented programming techniques and is built on a model-view-controller web application framework. It includes features such as page caching, RSS feeds, printable versions of pages, news flashes, blogs, polls, search, and support for language internationalization.
CVE-2024-21722: Joomla versions 3.2.0-3.10.14-elts, 4.0.0-4.4.2, 5.0.0-5.0.2 is vulnerable to session misconfiguration vulnerability.
Affected Version:
Joomla! CMS versions from 3.2.0 prior to 3.10.15-elts
Joomla! CMS versions from 4.0.0 prior to 4.4.3
Joomla! CMS versions from 5.0.0 prior to 5.0.3
Fixed Version:
Upgrade to version 3.10.15-elts, 4.4.3 or 5.0.3
QID Detection Logic(Unauthenticated):
QID checks for the Vulnerable version of Joomla.
Successful exploitation of this vulnerability may allow an attacker to use existing user sessions when a user's MFA methods have been modified.
- 20240201 -
developer.joomla.org/security-centre.html
CVEs related to QID 731192
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| 20240201 |
|