Annunci sicurezza Joomla!

    • Project: Joomla!
    • SubProject: CMS
    • Severity: High
    • Versions: 1.7.3 - 3.7.2
    • Exploit type: Information Disclosure
    • Reported Date: 2016-Feb-05
    • Fixed Date: 2017-July-04
    • CVE Number: CVE-2017-9933

    Description

    Improper cache invalidation leads to disclosure of form contents.

    Affected Installs

    Joomla! CMS versions 1.7.3-3.7.2

    Solution

    Upgrade to version 3.7.3

    Contact

    The JSST at the Joomla! Security Centre.

    Reported By: Jeff Channell
    • Project: Joomla!
    • SubProject: CMS
    • Severity: High
    • Versions: 1.7.3 - 3.7.2
    • Exploit type: XSS
    • Reported Date: 2017-June-04
    • Fixed Date: 2017-July-04
    • CVE Number: CVE-2017-9934

    Description

    Missing CSRF token checks and improper input validation lead to an XSS vulnerability.

    Affected Installs

    Joomla! CMS versions 1.7.3-3.7.2

    Solution

    Upgrade to version 3.7.3

    Contact

    The JSST at the Joomla! Security Centre.

    Reported By: Envo
    • Project: Joomla!
    • SubProject: CMS
    • Severity: Low
    • Versions: 1.5.0 through 3.7.2
    • Exploit type: XSS
    • Reported Date: 2017-June-22
    • Fixed Date: 2017-July-04
    • CVE Number: CVE-2017-7985

    Description

    Inadequate filtering of multibyte characters leads to XSS vulnerabilities in various components.

    Affected Installs

    Joomla! CMS versions 1.5.0 through 3.6.5

    Solution

    Upgrade to version 3.7.3

    Contact

    The JSST at the Joomla! Security Centre.

    Reported By: Fortinet's FortiGuard Labs
    • Project: Joomla!
    • SubProject: CMS
    • Severity: High
    • Versions: 3.7.0
    • Exploit type: SQL Injection
    • Reported Date: 2017-May-11
    • Fixed Date: 2017-May-17
    • CVE Number: CVE-2017-8917

    Description

    Inadequate filtering of request data leads to a SQL Injection vulnerability.

    Affected Installs

    Joomla! CMS versions 3.7.0

    Solution

    Upgrade to version 3.7.1

    Contact

    The JSST at the Joomla! Security Centre.

    Reported By: Marc-Alexandre Montpas / sucuri.net
    • Project: Joomla!
    • SubProject: CMS
    • Severity: Low
    • Versions: 3.4.0 through 3.6.5
    • Exploit type: Information Disclosure
    • Reported Date: 2016-Feb-06
    • Fixed Date: 2017-April-25
    • CVE Number: CVE-2017-8057

    Description

    Multiple files caused full path disclosures on systems with enabled error reporting.

    Affected Installs

    Joomla! CMS versions 3.4.0 through 3.6.5

    Solution

    Upgrade to version 3.7.0

    Contact

    The JSST at the Joomla! Security Centre.

    Reported By: Sim of tencent security