CVE-2024-40749: [20250103] - Core - Read ACL violation in multiple core views
Published Jan 7, 2025
·Updated
Improper Access Controls allows access to protected views.
Affected Software
3 affected components
Joomla Joomla\!>=3.9.0<3.10.20
Joomla Joomla\!>=4.0.0<4.4.10
Joomla Joomla\!>=5.0.0<5.2.3
Event History
Jan 7, 2025
CVE Published
via MITRE·04:22 PM
Data Sourced
via MITRE·04:22 PM
DescriptionWeakness
Data Sourced
via NVD·05:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-40749?
CVE-2024-40749 is classified as a medium severity vulnerability due to its improper access controls which allow unauthorized access to protected views.
2
How do I fix CVE-2024-40749?
To fix CVE-2024-40749, update your Joomla installation to version 3.10.20 or later, or 4.4.10 or later, or 5.2.3 or later.
3
What versions of Joomla are affected by CVE-2024-40749?
CVE-2024-40749 affects Joomla versions from 3.9.0 to 3.10.20, 4.0.0 to 4.4.10, and 5.0.0 to 5.2.3.
4
What types of attacks can exploit CVE-2024-40749?
CVE-2024-40749 can be exploited to gain unauthorized access to sensitive information by bypassing access controls.
5
Who should be concerned about CVE-2024-40749?
Website maintainers and administrators using affected Joomla versions should be concerned about CVE-2024-40749 due to the risk of unauthorized data access.