Joomla! 3.4.4 < 3.6.4 - Account Creation / Privilege Escalation vulnerability
Description:
CVE-2016-8869: The register method in the UsersModelRegistration class in controllers/user.php in the Users component in Joomla! before 3.6.4 allows remote attackers to gain privileges by leveraging incorrect use of unfiltered data when registering on a site.
CVE-2016-8870: The register method in the UsersModelRegistration class in controllers/user.php in the Users component in Joomla! before 3.6.4, when registration has been disabled, allows remote attackers to create user accounts by leveraging failure to check the Allow User Registration configuration setting.
Impact: Vulnerable joomla version allows remote users to create accounts and increase their privileges on any Joomla site
Mitigation: Vendor has released patch version.
- Patched Version: 3.6.4 (Reference: https://downloads.joomla.org/)
Reference URL’s:
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-8869
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-8870
- https://blog.sucuri.net/2016/10/joomla-mass-exploits-privilege-vulnerability.html
- https://developer.joomla.org/security-centre/659-20161001-core-account-creation.html
- https://developer.joomla.org/security-centre/660-20161002-core-elevated-privileges.html
Recommended Posts
Enhancing Situational Awareness on Emerging Cyber Threats
09 Sep 2023 - English articles, News, Security Advisories & Alerts, Uncategorized

UPDATE ON SITUATIONAL ALERT
08 Aug 2023 - Articles, News, Security Advisories & Alerts, Uncategorized