Junglewise Threat Intelligence

CVE-2016-9081: Joomla! CMS account modification and password reset vulnerability

CVE-2016-9081 · Severity: critical · CVSS 9.8 · Published 2017-01-23

Technologies: Joomla\!. Vendors: Joomla.

Executive brief

Joomla!, a popular website management platform, contains a critical security flaw that allows unauthorized individuals to take over user accounts. An attacker can remotely reset usernames, passwords, and administrative permissions for any existing account. This could lead to a complete website takeover, loss of sensitive data, and unauthorized changes to site content.

Technical details

A vulnerability in Joomla! CMS versions 3.4.4 through 3.6.3 stems from the incorrect use of unfiltered data during account management processes. This flaw allows a remote, unauthenticated attacker to modify existing user accounts via unspecified vectors. Specifically, an attacker can reset account credentials (username and password) and elevate privileges by modifying user group assignments. The issue is categorized under Credentials Management Errors (CWE-255). A patch is available in Joomla! version 3.6.4.

Affected products

  • Joomla! Joomla! CMS 3.4.4 through 3.6.3

Timeline

  • 2016-10-25: patched: Fixed in version 3.6.4
  • 2016-10-26: disclosed: Reported to the Joomla! Security Strike Team
  • 2017-01-23: advisory: NVD publication date

References

Related threats