PT-2018-14227 · Open Source Matters · Joomla!

Paul Freeman

·

Published

2018-10-09

·

Updated

2020-08-24

·

CVE-2018-17855

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Joomla! versions prior to 3.8.13
Description An issue was discovered where an attacker who gains access to the mail account of a user authorized to approve admin verifications in the registration process can activate themselves as an admin.
Recommendations For versions prior to 3.8.13, update to version 3.8.13 or later to resolve the issue.

Fix

Improper Privilege Management

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2018-17855

Affected Products

Joomla!