Description
Joomla! 3.4.4 through 3.6.3 allows attackers to reset username, password, and user group assignments and possibly perform other user account modifications via unspecified vectors.
References (2)
Core 2
Core References
Third Party Advisory, VDB Entry vdb-entry
x_refsource_bid
http://www.securityfocus.com/bid/93969
Patch, Vendor Advisory x_refsource_confirm
https://developer.joomla.org/security-centre/661-20161003-core-account-modifications.html
Scores
CVSS v3
9.8
EPSS
0.0023
EPSS Percentile
45.9%
Attack Vector
NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Details
CWE
CWE-255
Status
published
Products (11)
joomla/joomla\!
3.4.4
joomla/joomla\!
3.4.5
joomla/joomla\!
3.4.6
joomla/joomla\!
3.4.7
joomla/joomla\!
3.4.8 (2 CPE variants)
joomla/joomla\!
3.5.0 (10 CPE variants)
joomla/joomla\!
3.5.1 (3 CPE variants)
joomla/joomla\!
3.6.0 (6 CPE variants)
joomla/joomla\!
3.6.1 (3 CPE variants)
joomla/joomla\!
3.6.2
... and 1 more
Published
Jan 23, 2017
Tracked Since
Feb 18, 2026