CVE-2023-23752: [20230201] - Core - Improper access check in webservice endpoints
An issue was discovered in Joomla! 4.0.0 through 4.2.7. An improper access check allows unauthorized access to webservice endpoints.
Other sources
Joomla! contains an improper access control vulnerability that allows unauthorized access to webservice endpoints.
— CISA
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Compensating control
Apply mitigations per vendor instructions where available. If vendor mitigations are unavailable, discontinue use of Joomla versions 4.0.0 through 4.2.7.
Event History
Frequently Asked Questions
What is the vulnerability ID of this Joomla issue?
The vulnerability ID for this Joomla issue is CVE-2023-23752.
What is the severity of CVE-2023-23752?
The severity of CVE-2023-23752 is medium with a severity value of 5.3.
What is the description of CVE-2023-23752?
CVE-2023-23752 is an issue in Joomla! 4.0.0 through 4.2.7 that allows unauthorized access to webservice endpoints due to an improper access check.
How does CVE-2023-23752 affect Joomla?
CVE-2023-23752 affects Joomla versions 4.0.0 through 4.2.7.
Is there a fix available for CVE-2023-23752?
Yes, a fix is available for CVE-2023-23752. It is recommended to update to the latest version of Joomla to mitigate this vulnerability.