CVE-2024-21723: [20240202] - Core - Open redirect in installation application
Published Feb 20, 2024
·Updated
Inadequate parsing of URLs could result into an open redirect.
Affected Software
3 affected components
Joomla Joomla\!>=1.5.0<3.10.15
Joomla Joomla\!>=4.0.0<4.4.3
Joomla Joomla\!>=5.0.0<5.0.3
Event History
Feb 20, 2024
CVE Published
via MITRE·04:23 PM
Data Sourced
via MITRE·04:23 PM
DescriptionWeakness
Feb 29, 2024
Data Sourced
via NVD·01:44 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-21723?
CVE-2024-21723 is classified as a medium severity vulnerability due to its potential for open redirect attacks.
2
How do I fix CVE-2024-21723?
To fix CVE-2024-21723, update your Joomla installation to the latest version beyond 3.10.15, 4.4.3, or 5.0.3.
3
What is the impact of CVE-2024-21723 on my Joomla website?
The impact of CVE-2024-21723 is that it may allow attackers to redirect users to malicious websites, increasing the risk of phishing attacks.
4
Which versions of Joomla are affected by CVE-2024-21723?
CVE-2024-21723 affects Joomla versions from 1.5.0 to 3.10.15, 4.0.0 to 4.4.3, and 5.0.0 to 5.0.3.
5
Is there a workaround for CVE-2024-21723 if I can't update Joomla immediately?
Yes, a temporary workaround for CVE-2024-21723 is to avoid using URL parameters that could be manipulated for redirects until you can apply the update.