CVE-2016-8869: Input Validation
Published Nov 4, 2016
·Updated
The register method in the UsersModelRegistration class in controllers/user.php in the Users component in Joomla! before 3.6.4 allows remote attackers to gain privileges by leveraging incorrect use of unfiltered data when registering on a site.
Affected Software
1 affected component
Joomla Joomla\!<=3.6.3
Remediation
Event History
Nov 4, 2016
CVE Published
via MITRE·09:00 PM
Data Sourced
via MITRE·09:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2016-8869?
CVE-2016-8869 has a high severity rating due to its potential for privilege escalation.
2
How can I fix CVE-2016-8869?
To fix CVE-2016-8869, upgrade Joomla! to version 3.6.4 or later.
3
What type of attack does CVE-2016-8869 allow?
CVE-2016-8869 allows remote attackers to gain elevated privileges through registration exploits.
4
Which Joomla! versions are affected by CVE-2016-8869?
CVE-2016-8869 affects Joomla! versions prior to 3.6.4.
5
What component of Joomla! is involved in CVE-2016-8869?
CVE-2016-8869 involves the Users component, specifically the UsersModelRegistration class.