An issue was discovered in Joomla! before 3.8.13. If an attacker gets access to the mail account of an user who can approve admin verifications in the registration process, he can activate himself.
References
Link | Resource |
---|---|
http://www.securityfocus.com/bid/105559 | Third Party Advisory VDB Entry |
http://www.securitytracker.com/id/1041914 | Third Party Advisory VDB Entry |
https://developer.joomla.org/security-centre/754-20181004-core-acl-violation-in-com-users-for-the-admin-verification | Vendor Advisory |
http://www.securityfocus.com/bid/105559 | Third Party Advisory VDB Entry |
http://www.securitytracker.com/id/1041914 | Third Party Advisory VDB Entry |
https://developer.joomla.org/security-centre/754-20181004-core-acl-violation-in-com-users-for-the-admin-verification | Vendor Advisory |
Configurations
History
21 Nov 2024, 03:55
Type | Values Removed | Values Added |
---|---|---|
References | () http://www.securityfocus.com/bid/105559 - Third Party Advisory, VDB Entry | |
References | () http://www.securitytracker.com/id/1041914 - Third Party Advisory, VDB Entry | |
References | () https://developer.joomla.org/security-centre/754-20181004-core-acl-violation-in-com-users-for-the-admin-verification - Vendor Advisory |
Information
Published : 2018-10-09 21:29
Updated : 2024-11-21 03:55
NVD link : CVE-2018-17855
Mitre link : CVE-2018-17855
CVE.ORG link : CVE-2018-17855
JSON object : View
Products Affected
joomla
- joomla\!
CWE
CWE-269
Improper Privilege Management