Anuncios de seguridad Joomla

    • Project: Joomla!
    • SubProject: CMS
    • Impact: Moderate
    • Severity: High
    • Versions:4.0.0
    • Exploit type: Incorrect Access Control
    • Reported Date: 2021-08-20
    • Fixed Date: 2021-08-24
    • CVE Number: CVE-2021-26040

    Description

    The media manager does not correctly check the user's permissions before executing a file deletion command.

    Affected Installs

    Joomla! CMS versions 4.0.0

    Solution

    Upgrade to version 4.0.1

    Contact

    The JSST at the Joomla! Security Centre.

    Reported By:Maverick
    • Project: Joomla!
    • SubProject: CMS
    • Impact: Moderate
    • Severity: Low
    • Versions:3.0.0 - 3.9.27
    • Exploit type: XSS
    • Reported Date: 2021-06-22
    • Fixed Date: 2021-07-06
    • CVE Number: CVE-2021-26039

    Description

    Inadequate escaping in the imagelist view of com_media leads to a XSS vulnerability.

    Affected Installs

    Joomla! CMS versions 3.0.0 - 3.9.27

    Solution

    Upgrade to version 3.9.28

    Contact

    The JSST at the Joomla! Security Centre.

    Reported By:Hagai Wechsler / WhiteSourceSoftware
    • Project: Joomla!
    • SubProject: CMS
    • Impact: High
    • Severity: Low
    • Versions:2.5.0 - 3.9.27
    • Exploit type: Incorrect Access Control
    • Reported Date: 2021-06-06
    • Fixed Date: 2021-07-06
    • CVE Number: CVE-2021-26038

    Description

    Install action in com_installer lack the required hardcoded ACL checks for superusers, leading to various potential attack vectors. A default system is not affected cause by default com_installer is limited to super users already.

    Affected Installs

    Joomla! CMS versions 2.5.0 - 3.9.27

    Solution

    Upgrade to version 3.9.28

    Contact

    The JSST at the Joomla! Security Centre.

    Reported By:Nicholas Dionysopoulos
    • Project: Joomla!
    • SubProject: CMS
    • Impact: Moderate
    • Severity: Low
    • Versions:2.5.0 - 3.9.27
    • Exploit type: Incorrect Session Handling
    • Reported Date: 2019-02-08
    • Fixed Date: 2021-07-06
    • CVE Number: CVE-2021-26037

    Description

    Various CMS functions did not properly termine existing user sessions when a user's password was changed or the user was blocked.

    Affected Installs

    Joomla! CMS versions 2.5.0 - 3.9.27

    Solution

    Upgrade to version 3.9.28

    Contact

    The JSST at the Joomla! Security Centre.

    Reported By:Carsten Schmitz, Atik Islam, Dennis Hermatski, Muhammad Hussain, th3lawbreaker, Hoang Kien
    • Project: Joomla!
    • SubProject: CMS
    • Impact: Low
    • Severity: Low
    • Versions:2.5.0 - 3.9.27
    • Exploit type: DoS
    • Reported Date: 2021-06-08
    • Fixed Date: 2021-07-06
    • CVE Number: CVE-2021-26036

    Description

    Missing validation of input could lead to a broken usergroups table.

    Affected Installs

    Joomla! CMS versions 2.5.0 - 3.9.27

    Solution

    Upgrade to version 3.9.28

    Contact

    The JSST at the Joomla! Security Centre.

    Reported By: Hoang Kien from VSEC