CVE-2016-9081

CRITICAL

Joomla! <3.6.3 - Privilege Escalation

Title source: llm
STIX 2.1

Description

Joomla! 3.4.4 through 3.6.3 allows attackers to reset username, password, and user group assignments and possibly perform other user account modifications via unspecified vectors.

References (2)

Core 2
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/93969

Scores

CVSS v3 9.8
EPSS 0.0023
EPSS Percentile 45.9%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-255
Status published
Products (11)
joomla/joomla\! 3.4.4
joomla/joomla\! 3.4.5
joomla/joomla\! 3.4.6
joomla/joomla\! 3.4.7
joomla/joomla\! 3.4.8 (2 CPE variants)
joomla/joomla\! 3.5.0 (10 CPE variants)
joomla/joomla\! 3.5.1 (3 CPE variants)
joomla/joomla\! 3.6.0 (6 CPE variants)
joomla/joomla\! 3.6.1 (3 CPE variants)
joomla/joomla\! 3.6.2
... and 1 more
Published Jan 23, 2017
Tracked Since Feb 18, 2026