vendor:
Joomla!
by:
cf
7,5
CVSS
HIGH
Admin TakeOver
287
CWE
Product Name: Joomla!
Affected Version From: 3.6.4
Affected Version To: 3.6.4
Patch Exists: YES
Related CWE: CVE-2016-9838
CPE: a:joomla:joomla
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: None
2016
Joomla! <= 3.6.4 Admin TakeOver
This exploit allows an attacker to take over an administrator account in Joomla! versions 3.6.4 and below. The exploit works by sending two POST requests to the Joomla! registration form. The first request is sent with mismatched passwords, which is rejected by the server. The second request is sent with the same data, but with the passwords matching. This request is accepted by the server, and the attacker is able to take over the administrator account.
Mitigation:
Upgrade to Joomla! 3.6.5 or later.