First published: Tue Oct 09 2018(Updated: )
An issue was discovered in Joomla! before 3.8.13. com_installer actions do not have sufficient CSRF hardening in the backend.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Joomla | >=2.5.0<3.8.13 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-17858 has a medium severity level due to insufficient CSRF hardening.
To fix CVE-2018-17858, upgrade Joomla! to version 3.8.13 or later.
CVE-2018-17858 affects Joomla! versions prior to 3.8.13.
CVE-2018-17858 involves insufficient CSRF protection in com_installer actions within the Joomla! backend.
Yes, CVE-2018-17858 is exploitable due to the lack of proper CSRF hardening.