HomeSecurityJoomla 3.4.5 SQL Injection Vulnerability Fixes

Joomla 3.4.5 SQL Injection Vulnerability Fixes

In yesterday's announcement, the Drupal team announced a fix regarding the platform's security, and now the Joomla team is following suit, but it addressed three different issues, one of which is a SQL injection vulnerability that was classified as critical.

Joomla 3.4.5 SQL Injection Vulnerability Fixes
Joomla 3.4.5 Fixes SQL Injection Vulnerability, Which Issue Is Stated as "Insufficient Filtering of Data Requests"

According to the information available so far, the issue is stated as "insufficient filtering of data requests" and affects the Joomla and all versions from 3.2 to 3.4.4. Future details about the issue will be available after the vulnerabilities: CVE-2015-7297, CVE-2015-7857 and CVE-2015-7858.

In addition to SQL injection, two more vulnerabilities were found and fixed in the com_contenthistory and com_content functions that allowed attackers to access data that is prohibited for unauthorized users.

These vulnerabilities affect Joomla installations from 3.2 to 3.4.4 (com_contenthistory) and from 3.0 to 3.4.4 (com_content).

These vulnerabilities affect installations from 3.2 through 3.4.4 (com_contenthistory) and from 3.0 through 3.4.4 (com_content)
These vulnerabilities affect Joomla installations from 3.2 to 3.4.4 (com_contenthistory) and from 3.0 to 3.4.4 (com_content)

All users are urged to upgrade their platforms as soon as possible to prevent any attack on their website code. Apart from the three security fixes, there are no other changes to the CMS code.

You can download the latest version of Joomla CMS from its official website or GitHub.

Finally, Trustwave researchers released in-depth details about the SQL Injection they found on their blog.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS