An issue was discovered in Joomla! before 3.8.13. If an attacker gets access to the mail account of an user who can approve admin verifications in the registration process, he can activate himself.
References
Link | Resource |
---|---|
http://www.securityfocus.com/bid/105559 | Third Party Advisory VDB Entry |
http://www.securitytracker.com/id/1041914 | Third Party Advisory VDB Entry |
https://developer.joomla.org/security-centre/754-20181004-core-acl-violation-in-com-users-for-the-admin-verification | Vendor Advisory |
History
No history.
MITRE Information
Status: PUBLISHED
Assigner: mitre
Published: 2018-10-09T21:00:00
Updated: 2018-10-20T09:57:01
Reserved: 2018-10-01T00:00:00
Link: CVE-2018-17855
JSON object: View
NVD Information
Status : Analyzed
Published: 2018-10-09T21:29:00.543
Modified: 2020-08-24T17:37:01.140
Link: CVE-2018-17855
JSON object: View
Redhat Information
No data.
CWE