Junglewise Threat Intelligence

CVE-2023-23752: Joomla! Improper Access Control Vulnerability

CVE-2023-23752 · Severity: critical · CVSS 5.3 · Exploited in the wild · Published 2024-01-08

Technologies: Joomla\!, Joomla!, Joomla! Project Joomla! CMS. Vendors: Joomla, Joomla!, Joomla! Project.

Executive brief

Joomla! versions 4.0.0 through 4.2.7 contain an improper access control vulnerability within webservice endpoints. This flaw allows unauthorized remote attackers to bypass access checks and gain access to sensitive information or restricted endpoints.

Affected products

  • Joomla! Project Joomla! 4.0.0 through 4.2.7

Timeline

  • 2023-02-16: disclosed: NVD Published Date
  • 2024-01-08: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
  • 2023-02-01: advisory: Vendor advisory published by Joomla! Project

Related threats