CVE-2018-17858: CSRF
Published Oct 9, 2018
·Updated
An issue was discovered in Joomla! before 3.8.13. cominstaller actions do not have sufficient CSRF hardening in the backend.
Affected Software
1 affected component
Joomla Joomla\!>=2.5.0<3.8.13
Event History
Oct 9, 2018
CVE Published
via MITRE·09:00 PM
Data Sourced
via MITRE·09:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2018-17858?
CVE-2018-17858 has a medium severity level due to insufficient CSRF hardening.
2
How do I fix CVE-2018-17858?
To fix CVE-2018-17858, upgrade Joomla! to version 3.8.13 or later.
3
What does CVE-2018-17858 affect?
CVE-2018-17858 affects Joomla! versions prior to 3.8.13.
4
What is the nature of the vulnerability in CVE-2018-17858?
CVE-2018-17858 involves insufficient CSRF protection in com_installer actions within the Joomla! backend.
5
Is CVE-2018-17858 exploitable?
Yes, CVE-2018-17858 is exploitable due to the lack of proper CSRF hardening.