There is always a great deal of Joomla! development activity underway and communicating with other developers in the community is essential. This site is a resource for anyone looking to build or maintain software based on the Joomla! platform.
Where to Start
- Project: Joomla!
- SubProject: com_content
- Severity: Moderate
- Versions: 1.5.14 and all previous 1.5 releases
- Exploit type: Front-End Editing
- Reported Date: 2009-September-05
- Fixed Date: 2009-November-03
Description
When logged into the front end with Author access, it was possible to replace an article written by another user.
Affected Installs
All 1.5.x installs prior to and including 1.5.14 are affected.
Solution
Upgrade to latest Joomla! version (1.5.15 or newer).
Contact
The JSST at the Joomla! Security Centre.
- Project: Joomla!
- SubProject: Framework
- Severity: Moderate
- Versions: 1.5.12 and all previous 1.5 releases
- Exploit type: Path Disclosure
- Reported Date: 2009-July-21
- Fixed Date: 2009-July-22
Description
Some files were missing the check for JEXEC. These scripts will then expose internal path information of the host.
Affected Installs
All 1.5.x installs prior to and including 1.5.12 are affected.
Solution
Upgrade to latest Joomla! version (1.5.13 or newer).
Contact
The JSST at the Joomla! Security Centre.
- Project: Joomla!
- SubProject: com_mailto
- Severity: Low
- Versions: 1.5.13 and all previous 1.5 releases
- Exploit type: Email
- Reported Date: 2009-July-28
- Fixed Date: 2009-July-30
Description
In com_mailto, it was possible to bypass timeout protection against sending automated emails.
Affected Installs
All 1.5.x installs prior to and including 1.5.13 are affected.
Solution
Upgrade to latest Joomla! version (1.5.14 or newer).
Contact
The JSST at the Joomla! Security Centre.