Executive brief
Joomla! versions 4.0.0 through 4.2.7 contain an improper access control vulnerability within webservice endpoints. This flaw allows unauthorized remote attackers to bypass access checks and gain access to sensitive information or restricted endpoints.
Affected products
- Joomla! Project Joomla! 4.0.0 through 4.2.7
Timeline
- 2023-02-16: disclosed: NVD Published Date
- 2024-01-08: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
- 2023-02-01: advisory: Vendor advisory published by Joomla! Project