CVE-2013-3056: Medium severity joomla vulnerability
Published May 3, 2013
·Updated
Joomla! 2.5.x before 2.5.10 and 3.0.x before 3.0.4 allows remote authenticated users to bypass intended privilege requirements and delete the private messages of arbitrary users via unspecified vectors.
Affected Software
14 affected components
Joomla Joomla\!=2.5.0
Joomla Joomla\!=2.5.1
Joomla Joomla\!=2.5.2
Joomla Joomla\!=2.5.3
Joomla Joomla\!=2.5.4
Joomla Joomla\!=2.5.5
Joomla Joomla\!=2.5.6
Joomla Joomla\!=2.5.7
Joomla Joomla\!=2.5.8
Joomla Joomla\!=2.5.9
Joomla Joomla\!=3.0.0
Joomla Joomla\!=3.0.1
Joomla Joomla\!=3.0.2
Joomla Joomla\!=3.0.3
Event History
May 3, 2013
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2013-3056?
CVE-2013-3056 is classified as a medium severity vulnerability.
2
How do I fix CVE-2013-3056?
To fix CVE-2013-3056, upgrade Joomla! to version 2.5.10 or later, or to version 3.0.4 or later.
3
Who is affected by CVE-2013-3056?
CVE-2013-3056 affects Joomla! versions 2.5.x before 2.5.10 and 3.0.x before 3.0.4.
4
What type of attack does CVE-2013-3056 allow?
CVE-2013-3056 allows remote authenticated users to bypass privilege requirements and delete private messages of arbitrary users.
5
What are common symptoms of exploitation of CVE-2013-3056?
Common symptoms include unauthorized deletion of user private messages in Joomla! applications.