Joomla! Developer News and Updates

Security Announcements
  • [20170501] - Core - SQL Injection
    • Project: Joomla!
    • SubProject: CMS
    • Severity: High
    • Versions: 3.7.0
    • Exploit type: SQL Injection
    • Reported Date: 2017-May-11
    • Fixed Date: 2017-May-17
    • CVE Number: CVE-2017-8917

    Description

    Inadequate filtering of request data leads to a SQL Injection vulnerability.

    Affected Installs

    Joomla! CMS versions 3.7.0

    Solution

    Upgrade to version 3.7.1

    Contact

    The JSST at the Joomla! Security Centre.

    Reported By: Marc-Alexandre Montpas / sucuri.net
  • [20170408] - Core - Information Disclosure
    • Project: Joomla!
    • SubProject: CMS
    • Severity: Low
    • Versions: 3.4.0 through 3.6.5
    • Exploit type: Information Disclosure
    • Reported Date: 2016-Feb-06
    • Fixed Date: 2017-April-25
    • CVE Number: CVE-2017-8057

    Description

    Multiple files caused full path disclosures on systems with enabled error reporting.

    Affected Installs

    Joomla! CMS versions 3.4.0 through 3.6.5

    Solution

    Upgrade to version 3.7.0

    Contact

    The JSST at the Joomla! Security Centre.

    Reported By: Sim of tencent security
  • [20170407] - Core - ACL Violations
    • Project: Joomla!
    • SubProject: CMS
    • Severity: Low
    • Versions: 3.2.0 through 3.6.5
    • Exploit type: ACL Violation
    • Reported Date: 2017-March-01
    • Fixed Date: 2017-April-25
    • CVE Number: CVE-2017-7989

    Description

    Inadequate mime type checks allowed low-privilege users to upload swf files even if they were explicitly forbidden.

    Affected Installs

    Joomla! CMS versions 3.2.0 through 3.6.5

    Solution

    Upgrade to version 3.7.0

    Contact

    The JSST at the Joomla! Security Centre.

    Reported By: Abdullah Hussam