First published: Tue Oct 09 2018(Updated: )
An issue was discovered in Joomla! before 3.8.13. If an attacker gets access to the mail account of an user who can approve admin verifications in the registration process, he can activate himself.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Joomla | >=1.5.0<3.8.13 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-17855 is classified as a critical vulnerability due to its potential to allow unauthorized activation of administrative accounts.
To fix CVE-2018-17855, users should upgrade to Joomla! version 3.8.13 or later.
CVE-2018-17855 affects all Joomla! installations prior to version 3.8.13 that allow user account management.
Attackers with access to a user's email can exploit CVE-2018-17855 to gain admin privileges and activate themselves.
CVE-2018-17855 affects all Joomla! versions from 1.5.0 through 3.8.12.