Joomla! 3.4.4 < 3.6.4 - Account Creation / Privilege Escalation vulnerability
by CIRT Team
Description:
CVE-2016-8869: The register method in the UsersModelRegistration class in controllers/user.php in the Users component in Joomla! before 3.6.4 allows remote attackers to gain privileges by leveraging incorrect use of unfiltered data when registering on a site.
CVE-2016-8870: The register method in the UsersModelRegistration class in controllers/user.php in the Users component in Joomla! before 3.6.4, when registration has been disabled, allows remote attackers to create user accounts by leveraging failure to check the Allow User Registration configuration setting.
Impact: Vulnerable joomla version allows remote users to create accounts and increase their privileges on any Joomla site
Mitigation: Vendor has released patch version.
- Patched Version: 3.6.4 (Reference: https://downloads.joomla.org/)
Reference URL’s:
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-8869
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-8870
- https://blog.sucuri.net/2016/10/joomla-mass-exploits-privilege-vulnerability.html
- https://developer.joomla.org/security-centre/659-20161001-core-account-creation.html
- https://developer.joomla.org/security-centre/660-20161002-core-elevated-privileges.html
Recommended Posts
Active Exploitation of Critical F5 BIG – IP Vulnerability (CVE–2023-46747) Uncovered in Bangladesh
06 Nov 2024 - Security Advisories & Alerts