First published: Fri Nov 04 2016(Updated: )
The register method in the UsersModelRegistration class in controllers/user.php in the Users component in Joomla! before 3.6.4 allows remote attackers to gain privileges by leveraging incorrect use of unfiltered data when registering on a site.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Joomla | <=3.6.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-8869 has a high severity rating due to its potential for privilege escalation.
To fix CVE-2016-8869, upgrade Joomla! to version 3.6.4 or later.
CVE-2016-8869 allows remote attackers to gain elevated privileges through registration exploits.
CVE-2016-8869 affects Joomla! versions prior to 3.6.4.
CVE-2016-8869 involves the Users component, specifically the UsersModelRegistration class.