An issue was discovered in Joomla! before 3.8.13. If an attacker gets access to the mail account of an user who can approve admin verifications in the registration process, he can activate himself.
References
Link | Resource |
---|---|
https://developer.joomla.org/security-centre/754-20181004-core-acl-violation-in-com-users-for-the-admin-verification | Vendor Advisory |
http://www.securityfocus.com/bid/105559 | Third Party Advisory VDB Entry |
http://www.securitytracker.com/id/1041914 | Third Party Advisory VDB Entry |
Configurations
Information
Published : 2018-10-09 14:29
Updated : 2020-08-24 10:37
NVD link : CVE-2018-17855
Mitre link : CVE-2018-17855
JSON object : View
CWE
CWE-269
Improper Privilege Management
Products Affected
joomla
- joomla\!