First published: Wed Jul 27 2011(Updated: )
Joomla! 1.6.x before 1.6.2 does not prevent page rendering inside a frame in a third-party HTML document, which makes it easier for remote attackers to conduct clickjacking attacks via a crafted web site.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Joomla | =1.6-beta15 | |
Joomla | =1.6-beta12 | |
Joomla | =1.6-beta3 | |
Joomla | =1.6-beta13 | |
Joomla | =1.6.1 | |
Joomla | =1.6-beta8 | |
Joomla | =1.6-beta5 | |
Joomla | =1.6.0 | |
Joomla | =1.6-beta1 | |
Joomla | =1.6-beta6 | |
Joomla | =1.6-beta7 | |
Joomla | =1.6-beta14 | |
Joomla | =1.6-beta11 | |
Joomla | =1.6-beta2 | |
Joomla | =1.6-alpha2 | |
Joomla | =1.6-alpha | |
Joomla | =1.6-beta4 | |
Joomla | =1.6-rc1 | |
Joomla | =1.6-beta9 | |
Joomla | =1.6-beta10 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2011-2892 is considered a medium severity vulnerability due to its potential for exploitation in clickjacking attacks.
To fix CVE-2011-2892, upgrade your Joomla! installation to version 1.6.2 or later.
CVE-2011-2892 affects Joomla! versions 1.6.0 to 1.6.1, including various beta versions up to 1.6-beta15.
CVE-2011-2892 allows attackers to conduct clickjacking attacks by rendering a page inside a frame on a malicious website.
A potential workaround for CVE-2011-2892 is to set appropriate X-Frame-Options in server settings to mitigate clickjacking risks.