Joomla Security Notice :: October 26, 2016

Started by Jason, October 26, 2016, 01:58:46 PM

Previous topic - Next topic

0 Members and 1 Guest are viewing this topic.

Jason

Joomla has emailed a security announcement.  If you use Joomla for your site, please check your version and upgrade accordingly.

The announcement is available on their site here:

https://developer.joomla.org/security-centre.html


Quote
Joomla! Security News

________________________________________
[20161002] - Core - Elevated Privileges
Posted: 25 Oct 2016 12:00 PM PDT
-Project: Joomla!
-SubProject: CMS
-Severity: High
-Versions: 3.4.4 through 3.6.3
-Exploit type: Elevated Privileges
-Reported Date: 2016-October-21
-Fixed Date: 2016-October-25
-CVE Number: CVE-2016-8869
Description
Incorrect use of unfiltered data allows for users to register on a site with elevated privileges.
Affected Installs
Joomla! CMS versions 3.4.4 through 3.6.3
Solution
Upgrade to version 3.6.4
Contact
The JSST at the Joomla! Security Centre.
Reported By: Davide Tampellini


[20161001] - Core - Account Creation
Posted: 25 Oct 2016 12:00 PM PDT
-Project: Joomla!
-SubProject: CMS
-Severity: High
-Versions: 3.4.4 through 3.6.3
-Exploit type: Account Creation
-Reported Date: 2016-October-18
-Fixed Date: 2016-October-25
-CVE Number: CVE-2016-8870
Description
Inadequate checks allows for users to register on a site when registration has been disabled.
Affected Installs
Joomla! CMS versions 3.4.4 through 3.6.3
Solution
Upgrade to version 3.6.4
Contact
The JSST at the Joomla! Security Centre.
Reported By: Demis Palma