There is always a great deal of Joomla! development activity underway and communicating with other developers in the community is essential. This site is a resource for anyone looking to build or maintain software based on the Joomla! platform.
Where to Start
- Project: Joomla!
- SubProject: CMS
- Severity: High
- Versions: 3.7.0
- Exploit type: SQL Injection
- Reported Date: 2017-May-11
- Fixed Date: 2017-May-17
- CVE Number: CVE-2017-8917
Description
Inadequate filtering of request data leads to a SQL Injection vulnerability.
Affected Installs
Joomla! CMS versions 3.7.0
Solution
Upgrade to version 3.7.1
Contact
The JSST at the Joomla! Security Centre.
- Project: Joomla!
- SubProject: CMS
- Severity: Low
- Versions: 3.4.0 through 3.6.5
- Exploit type: Information Disclosure
- Reported Date: 2016-Feb-06
- Fixed Date: 2017-April-25
- CVE Number: CVE-2017-8057
Description
Multiple files caused full path disclosures on systems with enabled error reporting.
Affected Installs
Joomla! CMS versions 3.4.0 through 3.6.5
Solution
Upgrade to version 3.7.0
Contact
The JSST at the Joomla! Security Centre.
- Project: Joomla!
- SubProject: CMS
- Severity: Low
- Versions: 3.2.0 through 3.6.5
- Exploit type: ACL Violation
- Reported Date: 2017-March-01
- Fixed Date: 2017-April-25
- CVE Number: CVE-2017-7989
Description
Inadequate mime type checks allowed low-privilege users to upload swf files even if they were explicitly forbidden.
Affected Installs
Joomla! CMS versions 3.2.0 through 3.6.5
Solution
Upgrade to version 3.7.0
Contact
The JSST at the Joomla! Security Centre.