Vulnerability Name: | CVE-2018-17855 (CCN-151280) | ||||||||||||
Assigned: | 2018-10-04 | ||||||||||||
Published: | 2018-10-04 | ||||||||||||
Updated: | 2020-08-24 | ||||||||||||
Summary: | An issue was discovered in Joomla! before 3.8.13. If an attacker gets access to the mail account of an user who can approve admin verifications in the registration process, he can activate himself. | ||||||||||||
CVSS v3 Severity: | 8.8 High (CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H) 7.7 High (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C)
4.6 Medium (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N/E:U/RL:O/RC:C)
| ||||||||||||
CVSS v2 Severity: | 6.5 Medium (CVSS v2 Vector: AV:N/AC:L/Au:S/C:P/I:P/A:P)
| ||||||||||||
Vulnerability Type: | CWE-269 | ||||||||||||
Vulnerability Consequences: | Bypass Security | ||||||||||||
References: | Source: MITRE Type: CNA CVE-2018-17855 Source: BID Type: Third Party Advisory, VDB Entry 105559 Source: CCN Type: BID-105559 Joomla! Core Multiple Security Vulnerabilities Source: SECTRACK Type: Third Party Advisory, VDB Entry 1041914 Source: CCN Type: Joomla! Developer Web site [20181004] - Core - ACL Violation in com_users for the admin verification Source: CONFIRM Type: Vendor Advisory https://developer.joomla.org/security-centre/754-20181004-core-acl-violation-in-com-users-for-the-admin-verification Source: XF Type: UNKNOWN joomla-cve201817855-sec-bypass(151280) | ||||||||||||
Vulnerable Configuration: | Configuration 1:![]() | ||||||||||||
BACK |