EXPOSURES › CVE-2023-23752
CVE-2023-23752
HIGH ⌖ ON CISA KEV · EXPLOITEDJoomla! CMS allows unauthorized access to webservice endpoints via improper access control, enabling attackers to bypass authentication and access sensitive data.
This vulnerability permits attackers to access Joomla! webservice endpoints without proper authorization, potentially exposing sensitive data and disrupting operations. DIB organizations must ensure Joomla! instances are patched and access controls are hardened to prevent unauthorized access to critical systems.
Shame score — The vulnerability allows unauthorized access to webservice endpoints, which is a significant security risk but not directly linked to ransomware or zero-day exploitation.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Joomla! contains an improper access control vulnerability that allows unauthorized access to webservice endpoints.