PT-2018-14227 · Open Source Matters · Joomla!

·

CVE-2018-17855

·

Published

2018-10-09

·

Updated

2020-08-24

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Joomla! versions prior to 3.8.13
Description An issue was discovered where an attacker who gains access to the mail account of a user authorized to approve admin verifications in the registration process can activate themselves as an admin.
Recommendations For versions prior to 3.8.13, update to version 3.8.13 or later to resolve the issue.

Fix

Improper Privilege Management

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2018-17855

Affected Products

Joomla!