Início
Tendências
Vulnerabilidades
Notícias
Pesquisadores
Por que dbugs?

Demis Palma

Pesquisador deJSST
#17152de 53,640
15.6CVSS total
Vulnerabilidades · 2
Alta
2
PT-2018-10481
7.5
2018-05-22
Open Source Matters · Joomla! · CVE-2018-11322
**Name of the Vulnerable Software and Affected Versions** Joomla! Core versions prior to 3.8.8 **Description** An issue was discovered that could allow PHAR files to be handled as executable PHP scripts by the webserver, depending on the server configuration. **Recommendations** For versions prior to 3.8.8, update to version 3.8.8 or later to resolve the issue.
PT-2016-7601
8.1
2016-11-04
Open Source Matters · Joomla! · CVE-2016-8870
**Name of the Vulnerable Software and Affected Versions** Joomla! versions prior to 3.6.4 **Description** The issue concerns the register method in the UsersModelRegistration class, which fails to check the Allow User Registration configuration setting when registration has been disabled. This allows remote attackers to create user accounts. **Recommendations** For versions prior to 3.6.4, update to version 3.6.4 or later to resolve the issue. As a temporary workaround, consider disabling the registration functionality until a patch is available. Restrict access to the Users component to minimize the risk of exploitation.