First published: Tue Jan 12 2021(Updated: )
An issue was discovered in Joomla! 3.0.0 through 3.9.23. The lack of ACL checks in the orderPosition endpoint of com_modules leak names of unpublished and/or inaccessible modules.
Credit: security@joomla.org
Affected Software | Affected Version | How to fix |
---|---|---|
Joomla Joomla\! | >=3.0.0<=3.9.23 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this Joomla! vulnerability is CVE-2021-23123.
CVE-2021-23123 has a severity rating of 5.3 (medium).
The affected software version range for this vulnerability is Joomla! 3.0.0 through 3.9.23.
This vulnerability in Joomla! com_modules can leak names of unpublished and/or inaccessible modules.
Yes, the fix for CVE-2021-23123 is available in the Joomla! version 3.9.24 and later.