This feed provides announcements of resolved security issues in Joomla! software releases.
For more information about the Joomla! Security Strike Team (JSST) and its processes, please review our Security article.
To report potential security issues, please follow the guidelines in the above referenced article. Please note that we are only able to provide support for the Joomla! CMS, Joomla! Framework, and *.joomla.org network of websites.
You can subscribe to notifications from this feed through a RSS reader.
Inadequate input filtering in com_fields leads to a XSS vulnerability in multiple field types, i.e. list, radio and checkbox.
Joomla! CMS versions 3.7.0 through 3.8.3
Upgrade to version 3.8.4
The JSST at the Joomla! Security Centre.
Lack of escaping in the module chromes leads to XSS vulnerabilities in the module system.
Joomla! CMS versions 3.0.0 through 3.8.3
Upgrade to version 3.8.4
The JSST at the Joomla! Security Centre.
A logic bug in com_fields exposed read-only information about a site's custom fields to unauthorized users.
Joomla! CMS versions 3.7.0 through 3.8.1
Upgrade to version 3.8.2
The JSST at the Joomla! Security Centre.
A bug allowed third parties to bypass a user's 2-factor-authentication method.
Joomla! CMS versions 3.2.0 through 3.8.1
Upgrade to version 3.8.2
The JSST at the Joomla! Security Centre.
Inadequate escaping in the LDAP authentication plugin can result in disclosure of username and password.
Joomla! CMS versions 1.5.0 through 3.8.1
Upgrade to version 3.8.2
The JSST at the Joomla! Security Centre.
A logic bug in a SQL query could lead to the disclosure of article intro texts when these articles are in the archived state.
Joomla! CMS versions 3.7.0 through 3.7.5
Upgrade to version 3.8.0
The JSST at the Joomla! Security Centre.
Inadequate escaping in the LDAP authentication plugin can result into a disclosure of username and password.
Joomla! CMS versions 1.5.0 through 3.7.5
Upgrade to version 3.8.0
The JSST at the Joomla! Security Centre.
The CMS installer application lacked a process to verify the users ownership of a webspace, potentially allowing users to gain control.
Please note: Already installed sites are not affected, as this issue is limited to the installer application!
Joomla! CMS versions 1.0.0 through 3.7.3
Upgrade to version 3.7.4
The JSST at the Joomla! Security Centre.
Inadequate filtering of potentially malicious HTML tags leads to XSS vulnerabilities in various components.
Joomla! CMS versions 1.5.0 through 3.7.3
Upgrade to version 3.7.4
The JSST at the Joomla! Security Centre.
Improper cache invalidation leads to disclosure of form contents.
Joomla! CMS versions 1.7.3-3.7.2
Upgrade to version 3.7.3
The JSST at the Joomla! Security Centre.
Missing CSRF token checks and improper input validation lead to an XSS vulnerability.
Joomla! CMS versions 1.7.3-3.7.2
Upgrade to version 3.7.3
The JSST at the Joomla! Security Centre.
Inadequate filtering of multibyte characters leads to XSS vulnerabilities in various components.
Joomla! CMS versions 1.5.0 through 3.6.5
Upgrade to version 3.7.3
The JSST at the Joomla! Security Centre.
Inadequate filtering of request data leads to a SQL Injection vulnerability.
Joomla! CMS versions 3.7.0
Upgrade to version 3.7.1
The JSST at the Joomla! Security Centre.
Multiple files caused full path disclosures on systems with enabled error reporting.
Joomla! CMS versions 3.4.0 through 3.6.5
Upgrade to version 3.7.0
The JSST at the Joomla! Security Centre.
Inadequate mime type checks allowed low-privilege users to upload swf files even if they were explicitly forbidden.
Joomla! CMS versions 3.2.0 through 3.6.5
Upgrade to version 3.7.0
The JSST at the Joomla! Security Centre.
Inadequate filtering of form contents lead allow to overwrite the author of an article.
Joomla! CMS versions 1.6.0 through 3.6.5
Upgrade to version 3.7.0
The JSST at the Joomla! Security Centre.
Inadequate escaping of file and folder names leads to XSS vulnerabilities in the template manager component.
Joomla! CMS versions 3.2.0 through 3.6.5
Upgrade to version 3.7.0
The JSST at the Joomla! Security Centre.
Inadequate filtering of specific HTML attributes leads to XSS vulnerabilities in various components.
Joomla! CMS versions 1.5.0 through 3.6.5
Upgrade to version 3.7.0
The JSST at the Joomla! Security Centre.
Inadequate filtering of multibyte characters leads to XSS vulnerabilities in various components.
Joomla! CMS versions 1.5.0 through 3.6.5
Upgrade to version 3.7.0
The JSST at the Joomla! Security Centre.
Inadequate filtering leads to XSS in the template manager component.
Joomla! CMS versions 3.2.0 through 3.6.5
Upgrade to version 3.7.0
The JSST at the Joomla! Security Centre.
Mail sent using the JMail API leaked the used PHPMailer version in the mail headers.
Joomla! CMS versions 1.5.0 through 3.6.5
Upgrade to version 3.7.0
The JSST at the Joomla! Security Centre.
All versions of the third-party PHPMailer library distributed with Joomla! versions up to 3.6.5 are vulnerable to a remote code execution vulnerability. This is patched in PHPMailer 5.2.20 which will be included with Joomla! 3.7. After analysis, the JSST has determined that through correct use of the JMail class, there are additional validations in place which make executing this vulnerability impractical within the Joomla environment. As well, the vulnerability requires being able to pass user input to a message's "from" address; all places in the core Joomla API which send mail use the sender address set in the global configuration and does not allow for user input to be set elsewhere. However, extensions which bundle a separate version of PHPMailer or do not use the Joomla API to send email may be vulnerable to this issue.
Generally, the Joomla project does not issue advisories regarding third party libraries, however given the severity of this issue we felt it important to advise our users that we are aware of this issue and we have determined that the additional validations in our API prevent triggering this vulnerability.
Joomla! CMS versions 1.5.0 through 3.6.5
No action required for Joomla users, the updated library will be included in the next scheduled release and additional mechanisms exist in Joomla core to prevent triggering the vulnerability. Users of the PHPMailer library separate from Joomla are advised to upgrade to 5.2.20 or newer ASAP.
The JSST at the Joomla! Security Centre.
Joomla! 3.6.5 includes additional security hardening mechanisms prepared by the JSST, thanks in part to issue reports from Fotis Evangelou and Nicholas Dionysopoulos, which restricts a user's ability to make potentially damaging configuration changes. This includes restricting the ability to set the "New User Registration Group" and "Guest User Group" to a group with Super User permissions and restricting the ability for a lesser privileged user to make user group assignment changes to users in a Super User group.
Additionally, we have modified the behavior of JUser::authorise() to only return a boolean value. Previously, this method could return either a boolean value or null because the underlying call to JAccess::check() can also return a null value; neither JUser::authorise() or JAccess::check() documented this though. We have determined that based on how the API is used that JUser::authorise() should only return a boolean value. If a developer requires the previous behavior of a null return value (which indicates an "implicit" denied state versus "explicit" signified by boolean false), they should use JAccess::check() instead. The documentation for JAccess::check() has been updated to indicate the null return value as well.
The JSST at the Joomla! Security Centre.
Inadequate ACL checks in the Beez3 com_content article layout override enables a user to view restricted content.
Joomla! CMS versions 3.0.0 through 3.6.4
Upgrade to version 3.6.5
The JSST at the Joomla! Security Centre.
Inadequate filesystem checks allowed files with alternative PHP file extensions to be uploaded.
Joomla! CMS versions 3.0.0 through 3.6.4
Upgrade to version 3.6.5
The JSST at the Joomla! Security Centre.