HomeSecurityOld versions of Joomla CMS are vulnerable to new vulnerability

Old versions of Joomla CMS are vulnerable to new vulnerability

Joomla Last week, Italian security Alessandro Groppo from Hacktive Security revealed a vulnerabilityaffecting older versions of the Joomla content management system (CMS), a very popular application for creating and managing websites.

According to the researcher, the vulnerability affects all versions of Joomla from 3.0.0 to 3.4.6.. These versions were released between September 2012 and December 2015.

Experienced hackers can easily exploit this vulnerability . In the meantime, the method for exploiting it has already been released online

This is a PHP object injection vulnerability. This vulnerability could allow hackers to remotely execute malicious code . For example, hackers could exploit the vulnerability through the Joomla CMS login form and execute code on the site 's server .

Researcher Groppo noted that the current vulnerability is similar to CVE-2015-8562, another zero-day vulnerability that appeared in 2015 in the Joomla system and also allowed remote code execution. However, they have no other common elements.

The Joomla vulnerability CVE-2015-8562 is still in use today. It was discovered in December 2015 and was a zero-day vulnerability. Hackers used it to take control of sites.

Old versions of Joomla CMS are vulnerable to new vulnerability

The current vulnerability affects a smaller number of Joomla sites, as it only affects Joomla 3.x versions. In contrast, the 2015 vulnerability can affect all versions (1.5.x, 2. x and 3.x).

However, the vulnerability discovered by Groppo causes more problems, as it is “completely server-independent.” The older vulnerability could only affect servers with PHP versions prior to 5.4.45, 5.5.29, or 5.6.13.

The good thing is that Joomla developers have been made aware of the issue and have taken care to release an updated version to fix the vulnerability.

Many website owners are using outdated CMS versions. Experts recommend that users update their systems to avoid being at risk from the vulnerability.

Any version of Joomla from 3.4.7 onwards can prevent hacker attacks

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr
Being your self, in a world that constantly tries to change you, is your greatest achievement

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS