There is always a great deal of Joomla! development activity underway and communicating with other developers in the community is essential. This site is a resource for anyone looking to build or maintain software based on the Joomla! platform.
Where to Start
- Project: Joomla!
- SubProject: com_mailto
- Severity: Low
- Versions: 1.5.13 and all previous 1.5 releases
- Exploit type: Email
- Reported Date: 2009-July-28
- Fixed Date: 2009-July-30
Description
In com_mailto, it was possible to bypass timeout protection against sending automated emails.
Affected Installs
All 1.5.x installs prior to and including 1.5.13 are affected.
Solution
Upgrade to latest Joomla! version (1.5.14 or newer).
Contact
The JSST at the Joomla! Security Centre.
- Project: Joomla!
- SubProject: TinyMCE editor
- Severity: Critical
- Versions: 1.5.12
- Exploit type: Image File upload
- Reported Date: 2009-July-22
- Fixed Date: 2009-July-22
Description
Tiny browser included with TinyMCE 3.0 editor allowed files to be uploaded and removed without logging in.
Affected Installs
Version 1.5.12 only
Solution
Upgrade to latest Joomla! version (1.5.13 or newer).
Contact
The JSST at the Joomla! Security Centre.
- Project: Joomla!
- SubProject: Site client
- Severity: Moderate
- Versions: 1.5.11 and all previous 1.5 releases
- Exploit type: XSS
- Reported Date: 2009-June-30
- Fixed Date: 2009-June-30
Description
An attacker can inject JavaScript or DHTML code that will be executed in the context of targeted user browser, allowing the attacker to steal cookies. HTTP_REFERER variable is not properly parsed.
Affected Installs
All 1.5.x installs prior to and including 1.5.11 are affected.
Solution
Upgrade to latest Joomla! version (1.5.12 or newer).
Contact
The JSST at the Joomla! Security Centre.