First published: Tue Dec 08 2009(Updated: )
The Kide Shoutbox (com_kide) component 0.4.6 for Joomla! does not properly perform authentication, which allows remote attackers to post messages with an arbitrary account name via an insertar action to index.php. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Joomla! | =0.4.6 | |
Joomla |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2009-4232 has not been assigned a specific CVSS score, but it poses a significant risk due to improper authentication allowing unauthorized message posting.
The recommended fix for CVE-2009-4232 is to upgrade the Kide Shoutbox component to a newer version that addresses the authentication vulnerability.
Exploitation of CVE-2009-4232 allows attackers to impersonate any user by posting messages under arbitrary account names, potentially damaging reputation and trust.
CVE-2009-4232 affects Kide Shoutbox version 0.4.6 specifically, which is a component used in Joomla! installations.
There are no specific workarounds for CVE-2009-4232; upgrading the component is the best way to mitigate the vulnerability.