First published: Tue May 22 2018(Updated: )
An issue was discovered in Joomla! Core before 3.8.8. The web install application would autofill password fields after either a form validation error or navigating to a previous install step, and display the plaintext password for the administrator account at the confirmation screen.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Joomla | <3.8.8 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2018-11325 is considered to be important as it exposes plaintext administrator passwords.
To fix CVE-2018-11325, upgrade Joomla! Core to version 3.8.8 or later.
Joomla! Core versions prior to 3.8.8 are affected by CVE-2018-11325.
CVE-2018-11325 describes a problem where the web install application would disclose the plaintext password of the administrator account.
Administrators using Joomla! versions before 3.8.8 are impacted by CVE-2018-11325.