Home
Home
Trends
Trends
Vulnerabilities
Vulnerabilities
News
News
Researchers
Researchers
Why dbugs?
Why dbugs?
Settings

Demis Palma

#18444of 56,330
15.6Total CVSS
Vulnerabilities · 2
High
2
PT-2018-10481
7.5
2018-05-22
Open Source Matters · Joomla! · CVE-2018-11322
**Name of the Vulnerable Software and Affected Versions** Joomla! Core versions prior to 3.8.8 **Description** An issue was discovered that could allow PHAR files to be handled as executable PHP scripts by the webserver, depending on the server configuration. **Recommendations** For versions prior to 3.8.8, update to version 3.8.8 or later to resolve the issue.
PT-2016-7601
8.1
2016-11-04
Open Source Matters · Joomla! · CVE-2016-8870
**Name of the Vulnerable Software and Affected Versions** Joomla! versions prior to 3.6.4 **Description** The issue concerns the register method in the UsersModelRegistration class, which fails to check the Allow User Registration configuration setting when registration has been disabled. This allows remote attackers to create user accounts. **Recommendations** For versions prior to 3.6.4, update to version 3.6.4 or later to resolve the issue. As a temporary workaround, consider disabling the registration functionality until a patch is available. Restrict access to the Users component to minimize the risk of exploitation.