vendor:
Joomla!
by:
cf
7,5
CVSS
HIGH
Account Creation
287
CWE
Product Name: Joomla!
Affected Version From: 2.5.2
Affected Version To: 2.5.2
Patch Exists: YES
Related CWE: CVE-2012-1563
CPE: 2.5.2
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: None
2016
Joomla! <= 2.5.2 Admin Creation
This exploit allows an attacker to create an admin account in Joomla! version 2.5.2 and below. The attacker can use a random username and email address, and a known password. The exploit works by sending two requests to the registration form, the first one with mismatched passwords and the second one with the correct password. This will create an admin account in the system.
Mitigation:
Upgrade to the latest version of Joomla! and ensure that all components are up to date.