Rewterz Threat Advisory – Zero-day for old Joomla CMS versions

Tuesday, October 8, 2019



Analysis Summary

A vulnerability in older versions of the Joomla content management system (CMS), a popular web-based application for building and managing websites.

It’s a PHP object injection that can lead to remote code execution (RCE) under certain scenarios. For example, it can be exploited via the Joomla CMS’ login form and can allow attackers to execute code on the site’s underlying server.

The vulnerability is trivial to exploit, and proof-of-concept exploit code has been published online.


Remote code execution

Affected Vendors


Affected Products

Joomla content management system (CMS) from versions 3.0.0 to 3.4.6.


Update to version of 3.4.7 or later.

Data Sheets

Corporate Brochure

Our Story



Managed Security

Upcoming Rewterz Trainings/Events

Rewterz News

  • 23, February 2020 Rewterz Threat Advisory – CVE-2019-16028 – Cisco Firepower Management Center
  • 17, February 2020 Rewterz Threat Alert – Satan ransomware rebrands as 5ss5c ransomware
  • 3, February 2020 Rewterz Threat Alert – Iranian Campaign Tailored to US Companies Introduces TONEDEAF 2.0
  • 3, February 2020 Rewterz Threat Alert – Spamhaus Phishing Scam Delivers Ursnif Malware

Copyright © Rewterz. All rights reserved.