Joomla! 3.4.4 < 3.6.4 - Account Creation / Privilege Escalation vulnerability
Description:
CVE-2016-8869: The register method in the UsersModelRegistration class in controllers/user.php in the Users component in Joomla! before 3.6.4 allows remote attackers to gain privileges by leveraging incorrect use of unfiltered data when registering on a site.
CVE-2016-8870: The register method in the UsersModelRegistration class in controllers/user.php in the Users component in Joomla! before 3.6.4, when registration has been disabled, allows remote attackers to create user accounts by leveraging failure to check the Allow User Registration configuration setting.
Impact: Vulnerable joomla version allows remote users to create accounts and increase their privileges on any Joomla site
Mitigation: Vendor has released patch version.
- Patched Version: 3.6.4 (Reference: https://downloads.joomla.org/)
Reference URL’s:
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-8869
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-8870
- https://blog.sucuri.net/2016/10/joomla-mass-exploits-privilege-vulnerability.html
- https://developer.joomla.org/security-centre/659-20161001-core-account-creation.html
- https://developer.joomla.org/security-centre/660-20161002-core-elevated-privileges.html
Recommended Posts
Cyber Threat Alert: New Variants of KASABLANKA LodaRAT infrastructure targeting Bangladesh
16 Feb 2021 - Security Advisories & Alerts
Hildegard Malware [cyberflorida]
14 Feb 2021 - Security Advisories & Alerts