First published: Wed Mar 30 2022(Updated: )
An issue was discovered in Joomla! 2.5.0 through 3.10.6 & 4.0.0 through 4.1.0. A user row was not bound to a specific authentication mechanism which could under very special circumstances allow an account takeover.
Credit: security@joomla.org
Affected Software | Affected Version | How to fix |
---|---|---|
Joomla Joomla\! | >=2.5.0<=3.10.6 | |
Joomla Joomla\! | >=4.0.0<=4.1.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-23795 is a vulnerability in Joomla! 2.5.0 through 3.10.6 & 4.0.0 through 4.1.0 that allows an account takeover under certain circumstances.
CVE-2022-23795 has a severity rating of 9.8 (Critical).
Joomla! versions 2.5.0 through 3.10.6 and 4.0.0 through 4.1.0 are affected by CVE-2022-23795.
An attacker can exploit CVE-2022-23795 by taking advantage of the user row not being bound to a specific authentication mechanism.
Yes, Joomla! has released a security update to address CVE-2022-23795. It is recommended to update to the latest version available.