Skip to content
COOEY

EXPOSURES › CVE-2023-23752

CVE-2023-23752

HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2024-01-08 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2023-23752 ↗
⌖ EXPLOITED IN THE WILD SHAME 45/100 exploited-in-wildunpatchedauth-bypass

Joomla! CMS allows unauthorized access to webservice endpoints via improper access control, enabling attackers to bypass authentication and access sensitive data.

This vulnerability permits attackers to access Joomla! webservice endpoints without proper authorization, potentially exposing sensitive data and disrupting operations. DIB organizations must ensure Joomla! instances are patched and access controls are hardened to prevent unauthorized access to critical systems.

Shame score — The vulnerability allows unauthorized access to webservice endpoints, which is a significant security risk but not directly linked to ransomware or zero-day exploitation.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

Joomla! contains an improper access control vulnerability that allows unauthorized access to webservice endpoints.

AFFECTED FEDRAMP PRODUCTS · 0
No correlated FedRAMP products.