Rewterz Threat Advisory – Zero-day for old Joomla CMS versions

Tuesday, October 8, 2019

Severity

Medium

Analysis Summary

A vulnerability in older versions of the Joomla content management system (CMS), a popular web-based application for building and managing websites.

It’s a PHP object injection that can lead to remote code execution (RCE) under certain scenarios. For example, it can be exploited via the Joomla CMS’ login form and can allow attackers to execute code on the site’s underlying server.

The vulnerability is trivial to exploit, and proof-of-concept exploit code has been published online.

Impact

Remote code execution

Affected Vendors

Joomla

Affected Products

Joomla content management system (CMS) from versions 3.0.0 to 3.4.6.

Remediation

Update to version of 3.4.7 or later.

Data Sheets

Corporate Brochure


Our Story


Services


Solutions


Managed Security


Upcoming Rewterz Trainings/Events

Rewterz News

  • 11, October 2019 Rewterz Threat Alert – Kimsuky Group – IOC’s
  • 11, October 2019 Rewterz Threat Advisory – CVE-2019-10936 – Siemens PROFINET Devices Denial of Service Vulnerability
  • 11, October 2019 Rewterz Threat Advisory – CVE-2019-10923 – Siemens Industrial Real-Time (IRT) Devices DoS Vulnerability
  • 10, October 2019 Rewterz Threat Alert – Another Agenttesla campaign using a compromised Iraq Government site

Copyright © Rewterz. All rights reserved.