Five vulnerabilities have been discovered in the Joomla content management system . Their immediate correction is essential, as the vulnerabilities could be used by a cybercriminal to execute malicious code on vulnerable sites.

Joomla has released updates that address the vulnerabilities. They affect multiple versions, so site administrators should take action immediately. The fixes are in versions 5.0.3 and 4.4.3 of the CMS.
See also: VMware: Recommends removal of EAP plugin due to vulnerabilities
Let's look at the five Joomla:
CVE-2024-21722: MFA management features do not properly terminate existing user sessions when a user.
CVE-2024-21723: Insufficient URL parsing could lead to an open redirect.
CVE-2024-21724: Insufficient input validation for media selection fields leads to cross-site scripting (XSS) in various extensions.
CVE-2024-21725: Insufficient escaping of email addresses leads to XSS vulnerabilities in various components
CVE-2024-21726: Insufficient content filtering within filter code leads to multiple XSS
According to Joomla, the CVE-2024-21725 vulnerability is the most serious of all and is most likely to be exploited by a cybercriminal.
Remote code execution
The vulnerability, CVE-2024-21726, affects Joomla's core filter component. It has a moderate severity and exploitability rating, but Stefan Schiller, a researcher at Sonar, believes it could be used for remote code execution.
“ Attackers can exploit the issue to perform remote code execution by tricking an administrator into clicking a malicious link ,” Schiller said
See also: 28,500 Exchange servers vulnerable to known vulnerability
XSS vulnerabilities, such as those in Joomla software, allow attackers to inject malicious scripts into content displayed to other users, allowing unsafe code to be executed through the victim's browser.
But as Schiller said, successful exploitation requires user interaction. An attacker would have to trick a user with administrative privileges into clicking a malicious link.
The need for user interaction reduces the severity of the vulnerability, but we have seen many times that attackers can become very persuasive and get the victim to follow their instructions. Alternatively, there are “ spray-and-pray ” attacks , where a larger audience is exposed to malicious links in the hope that some users will click.
It is worth noting that technical details about the vulnerability and how to exploit it have not been released, so that site administrators using Joomla have time to apply the available security.

Protection
Considering the above vulnerabilities, it is essential to apply the latest security update and in general you should keep Joomla and all your extensions up to date. Updates include security that can protect your website from known vulnerabilities.
Second, use strong and unique passwords for all your accounts. This includes Joomla administrator accounts, database accounts, and FTP accounts.
See also: Hackers exploit vulnerability in Bricks Builder WordPress Theme
Third, protect critical folders and files on your server. This can restrict access to important files and prevent malicious code from executing.
Fourth, use a Joomla security plugin, such as Akeeba Admin Tools. Such tools provide additional layers of protection, such as intruder detection, protection against brute force attacks, and isolation from malicious IP addresses.
Finally, always create and maintain regular backups of your website. In case your website is hacked, you will be able to restore it to a safe state.
Source: www.bleepingcomputer.com
