HomeInvestigationsGreeks identify zero-day vulnerability in CMS Joomla

Greeks identify zero-day vulnerability in Joomla CMS

SecNews received a critical report regarding a 0-day vulnerability identified by Greek researchers and affecting websites using the well-known CMS Joomla

Greek security researchers Dimitrios Roussis and Evangelos Apostoloudis have identified a critical vulnerability of high importance, which has not been published (0-day), and allows sql injection in the ja-k2-filter-and-search component ( https://www.joomlart.com/joomla/extensions/ja-k2-search ) of Joomla .

This particular component is currently used by hundreds of websites around the world. Through this vulnerability and with well-known available tools such as sqlmap, one can achieve a complete recovery of the website database, with a particularly easy process, revealing in some cases very critical data. There are not a few e-shop websites that, through this weakness, can expose sensitive information such as member details, personal data or even credit card numbers!Joomla zero-day

This vulnerability, which is considered to be of very high risk, as we mentioned above, has not been officially published by any international site (0-day vulnerability), is not known to the company that created the component, and has not been integrated into online databases of known vulnerabilities.

Evidence

For any Joomla that uses this specific component, we can detect the vulnerability with the following request:

code0day

As a result, the following error message appears, proving the existence of the vulnerability.

pic

Using sqlmap and the url we mentioned above, it is very easy to dump the database and read all the data.

Indicative websites

Some indicative pages (from a large set) that exhibit the vulnerability are listed below.

As the two researchers told SecNews, they will soon be publishing other 0-day findings they have identified on other platforms. Their update aims to strengthen the security of websites and infrastructures. We await their new achievements with particular interest!

SecNews thanks researchers Dimitrios Roussis and Evangelos Apostoloudis for the timely and accurate information.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SecNews
SecNewshttps://www.secnews.gr
In a world without fences and walls, who needs Gates and Windows

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS