CVE-2023-23752

MEDIUM KEV NUCLEI

Joomla! < 4.2.8 - Improper Access Control

Title source: rule

Description

An issue was discovered in Joomla! 4.0.0 through 4.2.7. An improper access check allows unauthorized access to webservice endpoints.

Exploits (56)

nomisec WORKING POC 92 stars
by Acceis · remote
https://github.com/Acceis/exploit-CVE-2023-23752
nomisec WORKING POC 35 stars
by ThatNotEasy · remote
https://github.com/ThatNotEasy/CVE-2023-23752
nomisec SCANNER 17 stars
by z3n70 · infoleak
https://github.com/z3n70/CVE-2023-23752
nomisec WORKING POC 15 stars
by K3ysTr0K3R · remote
https://github.com/K3ysTr0K3R/CVE-2023-23752-EXPLOIT
nomisec WORKING POC 12 stars
by keyuan15 · infoleak
https://github.com/keyuan15/CVE-2023-23752
nomisec SCANNER 7 stars
by adhikara13 · infoleak
https://github.com/adhikara13/CVE-2023-23752
nomisec SCANNER 7 stars
by gibran-abdillah · infoleak
https://github.com/gibran-abdillah/CVE-2023-23752
nomisec WORKING POC 5 stars
by Youns92 · infoleak
https://github.com/Youns92/Joomla-v4.2.8---CVE-2023-23752
nomisec WORKING POC 5 stars
by 0xNahim · remote
https://github.com/0xNahim/CVE-2023-23752
nomisec WORKING POC 4 stars
by Fernando-olv · remote
https://github.com/Fernando-olv/Joomla-CVE-2023-23752
nomisec WORKING POC 4 stars
by Sweelg · remote
https://github.com/Sweelg/CVE-2023-23752
nomisec WORKING POC 4 stars
by karthikuj · remote
https://github.com/karthikuj/CVE-2023-23752-Docker
nomisec SCANNER 3 stars
by ifacker · infoleak
https://github.com/ifacker/CVE-2023-23752-Joomla
nomisec WORKING POC 3 stars
by mil4ne · poc
https://github.com/mil4ne/CVE-2023-23752-Joomla-v4.2.8
nomisec SCANNER 3 stars
by Saboor-Hakimi · infoleak
https://github.com/Saboor-Hakimi/CVE-2023-23752
nomisec WRITEUP 3 stars
by Vulnmachines · infoleak
https://github.com/Vulnmachines/joomla_CVE-2023-23752
nomisec SCANNER 2 stars
by ibaiw · infoleak
https://github.com/ibaiw/joomla_CVE-2023-23752
nomisec WORKING POC 2 stars
by yusinomy · poc
https://github.com/yusinomy/CVE-2023-23752
nomisec SCANNER 2 stars
by GhostToKnow · infoleak
https://github.com/GhostToKnow/CVE-2023-23752
nomisec SCANNER 2 stars
by blacks1ph0n · infoleak
https://github.com/blacks1ph0n/CVE-2023-23752
nomisec WORKING POC 2 stars
by JohnDoeAnonITA · infoleak
https://github.com/JohnDoeAnonITA/CVE-2023-23752
nomisec WORKING POC 2 stars
by 0xWhoami35 · remote
https://github.com/0xWhoami35/CVE-2023-23752
nomisec SCANNER 1 stars
by TindalyTn · infoleak
https://github.com/TindalyTn/CVE-2023-23752
nomisec WORKING POC 1 stars
by Pushkarup · remote
https://github.com/Pushkarup/CVE-2023-23752
nomisec WORKING POC 1 stars
by r3dston3 · remote
https://github.com/r3dston3/CVE-2023-23752
nomisec WORKING POC 1 stars
by h3x0v3rl0rd · poc
https://github.com/h3x0v3rl0rd/CVE-2023-23752
github WORKING POC 1 stars
by JorgeRh4ck · pythonpoc
https://github.com/JorgeRh4ck/CVE-Exploits/tree/main/CVE-2023-23752
nomisec WORKING POC 1 stars
by AlissonFaoli · remote
https://github.com/AlissonFaoli/CVE-2023-23752
nomisec WORKING POC 1 stars
by wangking1 · infoleak
https://github.com/wangking1/CVE-2023-23752-poc
nomisec STUB
by shellvik · poc
https://github.com/shellvik/CVE-2023-23752
nomisec WORKING POC
by adriyansyah-mf · infoleak
https://github.com/adriyansyah-mf/CVE-2023-23752
nomisec WORKING POC
by Jenderal92 · infoleak
https://github.com/Jenderal92/Joomla-CVE-2023-23752
nomisec SCANNER
by AkbarWiraN · remote
https://github.com/AkbarWiraN/Joomla-Scanner
nomisec WORKING POC
by MrP4nda1337 · infoleak
https://github.com/MrP4nda1337/CVE-2023-23752
nomisec WORKING POC
by yTxZx · remote
https://github.com/yTxZx/CVE-2023-23752
nomisec SCANNER
by Ly0kha · infoleak
https://github.com/Ly0kha/Joomla-CVE-2023-23752-Exploit-Script
nomisec WORKING POC
by svaltheim · remote
https://github.com/svaltheim/CVE-2023-23752
nomisec WORKING POC
by C1ph3rX13 · remote
https://github.com/C1ph3rX13/CVE-2023-23752
nomisec WORKING POC
by mariovata · infoleak
https://github.com/mariovata/CVE-2023-23752-Python
nomisec WORKING POC
by 0xx01 · remote
https://github.com/0xx01/CVE-2023-23752
nomisec WORKING POC
by Aureum01 · remote
https://github.com/Aureum01/CVE-2023-23752
nomisec SCANNER
by sw0rd1ight · poc
https://github.com/sw0rd1ight/CVE-2023-23752
nomisec WORKING POC
by gunzf0x · remote
https://github.com/gunzf0x/CVE-2023-23752
nomisec WORKING POC
by hadrian3689 · remote
https://github.com/hadrian3689/CVE-2023-23752_Joomla
nomisec WORKING POC
by JeneralMotors · remote
https://github.com/JeneralMotors/CVE-2023-23752
nomisec WORKING POC
by Rival420 · remote
https://github.com/Rival420/CVE-2023-23752
github WORKING POC
by Kl3lCrypt · pythonpoc
https://github.com/Kl3lCrypt/cve-exploits/tree/main/CVE-2023-23752
nomisec SCANNER
by Ge-Per · poc
https://github.com/Ge-Per/Scanner-CVE-2023-23752
exploitdb WORKING POC VERIFIED
by Alexandre ZANNI · pythonwebappsphp
https://www.exploit-db.com/exploits/51334
metasploit WORKING POC
by h00die, Tianji Lab · rubypoc
https://github.com/rapid7/metasploit-framework/blob/master/modules/auxiliary/scanner/http/joomla_api_improper_access_checks.rb
vulncheck_xdb WORKING POC
remote
https://github.com/revkami/CVE-2023-23752-Joomla-v4.2.8
vulncheck_xdb WORKING POC
remote
https://github.com/0xVoodoo/PoCs
vulncheck_xdb WORKING POC
remote
https://github.com/n3rdh4x0r/CVE-2023-23752
vulncheck_xdb WORKING POC
remote
https://github.com/0x0jr/HTB-Devvortex-CVE-2023-2375-PoC
vulncheck_xdb WORKING POC
infoleak
https://github.com/Anekant-Singhai/Exploits

Nuclei Templates (1)

Joomla! Webservice - Password Disclosure
MEDIUMVERIFIEDby badboycxcc,Sascha Brendel
Shodan: html:"Joomla! - Open Source Content Management" || http.html:"joomla! - open source content management" || http.component:"joomla" || cpe:"cpe:2.3:a:joomla:joomla\!"
FOFA: body="joomla! - open source content management"

Scores

CVSS v3 5.3
EPSS 0.9453
EPSS Percentile 100.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

Exploitation Intel

CISA KEV 2024-01-08
VulnCheck KEV 2023-03-08
InTheWild.io 2023-03-23
ENISA EUVD EUVD-2023-27838

Classification

CWE
CWE-284
Status published

Affected Products (1)

joomla/joomla\! < 4.2.8

Timeline

Published Feb 16, 2023
KEV Added Jan 08, 2024
Tracked Since Feb 18, 2026