CVE-2018-17859: Medium severity joomla vulnerability
Published Oct 9, 2018
·Updated
An issue was discovered in Joomla! before 3.8.13. Inadequate checks in comcontact could allow mail submission in disabled forms.
Affected Software
1 affected component
Joomla Joomla\!>=2.5.0<3.8.13
Event History
Oct 9, 2018
CVE Published
via MITRE·09:00 PM
Data Sourced
via MITRE·09:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2018-17859?
CVE-2018-17859 has a moderate severity level as it involves inadequate checks that may allow unauthorized mail submissions.
2
How do I fix CVE-2018-17859?
To fix CVE-2018-17859, update your Joomla! installation to version 3.8.13 or later.
3
What versions of Joomla! are affected by CVE-2018-17859?
CVE-2018-17859 affects Joomla! versions before 3.8.13, including all versions from 2.5.0 up to 3.8.12.
4
What component in Joomla! is impacted by CVE-2018-17859?
CVE-2018-17859 impacts the com_contact component within Joomla!.
5
Can CVE-2018-17859 be exploited if contact forms are disabled?
Yes, CVE-2018-17859 can be exploited to allow mail submission even if contact forms are disabled.