First published: Tue Oct 09 2018(Updated: )
An issue was discovered in Joomla! before 3.8.13. com_joomlaupdate allows the execution of arbitrary code. The default ACL config enabled the ability of Administrator-level users to access com_joomlaupdate and trigger code execution.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
composer/joomla/framework | >=2.5.4<=3.8.12 | 3.8.13 |
Joomla | >=2.5.4<3.8.13 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-17856 has a high severity rating due to the ability for Administrator-level users to execute arbitrary code.
To fix CVE-2018-17856, upgrade your Joomla installation to version 3.8.13 or later.
CVE-2018-17856 affects the com_joomlaupdate component in Joomla! versions prior to 3.8.13.
CVE-2018-17856 can be exploited by Administrator-level users who have access to the com_joomlaupdate component.
The impact of CVE-2018-17856 is the potential execution of arbitrary code on vulnerable Joomla installations.