CVE-2018-11325: Critical severity Joomla Joomla\! vulnerability
Published May 22, 2018
·Updated
An issue was discovered in Joomla! Core before 3.8.8. The web install application would autofill password fields after either a form validation error or navigating to a previous install step, and display the plaintext password for the administrator account at the confirmation screen.
Affected Software
1 affected component
Joomla Joomla\!<3.8.8
Event History
May 22, 2018
CVE Published
via MITRE·03:00 PM
Data Sourced
via MITRE·03:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2018-11325?
The severity of CVE-2018-11325 is considered to be important as it exposes plaintext administrator passwords.
2
How do I fix CVE-2018-11325?
To fix CVE-2018-11325, upgrade Joomla! Core to version 3.8.8 or later.
3
What versions of Joomla! are affected by CVE-2018-11325?
Joomla! Core versions prior to 3.8.8 are affected by CVE-2018-11325.
4
What is the main issue described in CVE-2018-11325?
CVE-2018-11325 describes a problem where the web install application would disclose the plaintext password of the administrator account.
5
Who is impacted by CVE-2018-11325?
Administrators using Joomla! versions before 3.8.8 are impacted by CVE-2018-11325.