First published: Thu Nov 09 2017(Updated: )
In Joomla! before 3.8.2, a bug allowed third parties to bypass a user's 2-factor authentication method.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Joomla | >=3.2.0<=3.8.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-16634 has a medium severity rating due to its potential to compromise user authentication.
To fix CVE-2017-16634, upgrade Joomla! to version 3.8.2 or later.
CVE-2017-16634 affects all Joomla! versions before 3.8.2, specifically from 3.2.0 to 3.8.1.
Yes, CVE-2017-16634 can be exploited remotely, allowing attackers to bypass two-factor authentication.
CVE-2017-16634 affects the two-factor authentication functionality in Joomla!, enabling unauthorized access.