PT-2008-5045 · Joomla · Joomla!

D3M0N

·

Published

2008-08-14

·

Updated

2017-09-29

·

CVE-2008-3681

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Joomla! versions 1.5 through 1.5.5
Description The issue concerns improper validation of reset tokens in the components/com user/models/reset.php file. This allows remote attackers to reset the password of the first enabled user, which is typically the administrator.
Recommendations For Joomla! versions 1.5 through 1.5.5, update to a version that properly validates reset tokens to prevent unauthorized password resets.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2008-3681

Affected Products

Joomla!