CVE-2016-8870
The register method in the UsersModelRegistration class in controllers/user.php in the Users component in Joomla! before 3.6.4, when registration has been disabled, allows remote attackers to create user accounts by leveraging failure to check the Allow…
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 81.2%, higher than 100% of all known CVEs. Patch or mitigate before the next change window.
Description
The register method in the UsersModelRegistration class in controllers/user.php in the Users component in Joomla! before 3.6.4, when registration has been disabled, allows remote attackers to create user accounts by leveraging failure to check the Allow User Registration configuration setting.
- CVSS 3.0
- 8.1 HIGHCVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 81.21% probability · 100th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-20
- Affected
- joomla/joomla\!
- Source
- cve@mitre.org
References
- http://www.rapid7.com/db/modules/auxiliary/admin/http/joomla_registration_privescThird Party Advisory
- http://www.securityfocus.com/bid/93876Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1037107
- http://www.securitytracker.com/id/1037108Third Party Advisory, VDB Entry
- https://blog.sucuri.net/2016/10/details-on-the-privilege-escalation-vulnerability-in-joomla.html
- https://developer.joomla.org/security-centre/659-20161001-core-account-creation.htmlVendor Advisory
- https://github.com/joomla/joomla-cms/commit/bae1d43938c878480cfd73671e4945211538fdcfPatch
- https://medium.com/%40showthread/joomla-3-6-4-account-creation-elevated-privileges-write-up-and-exploit-965d8fb46fa2#.rq4qh1v4r
- https://www.exploit-db.com/exploits/40637/Exploit, Third Party Advisory
- http://www.rapid7.com/db/modules/auxiliary/admin/http/joomla_registration_privescThird Party Advisory
- http://www.securityfocus.com/bid/93876Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1037107
- http://www.securitytracker.com/id/1037108Third Party Advisory, VDB Entry
- https://blog.sucuri.net/2016/10/details-on-the-privilege-escalation-vulnerability-in-joomla.html
- https://developer.joomla.org/security-centre/659-20161001-core-account-creation.htmlVendor Advisory
- https://github.com/joomla/joomla-cms/commit/bae1d43938c878480cfd73671e4945211538fdcfPatch
- https://medium.com/%40showthread/joomla-3-6-4-account-creation-elevated-privileges-write-up-and-exploit-965d8fb46fa2#.rq4qh1v4r
- https://www.exploit-db.com/exploits/40637/Exploit, Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.