FreeBSD VuXML: Documenting security issues in FreeBSD and the FreeBSD Ports Collection

Joomla! -- multiple vulnerabilities

Affected packages
1.6.0 <= joomla3 < 3.6.5

Details

VuXML ID 624b45c0-c7f3-11e6-ae1b-002590263bf5
Discovery 2016-12-06
Entry 2016-12-22

The JSST and the Joomla! Security Center report:

[20161201] - Core - Elevated Privileges

Incorrect use of unfiltered data stored to the session on a form validation failure allows for existing user accounts to be modified; to include resetting their username, password, and user group assignments.

[20161202] - Core - Shell Upload

Inadequate filesystem checks allowed files with alternative PHP file extensions to be uploaded.

[20161203] - Core - Information Disclosure

Inadequate ACL checks in the Beez3 com_content article layout override enables a user to view restricted content.

References

CVE Name CVE-2016-9836
CVE Name CVE-2016-9837
CVE Name CVE-2016-9838
URL https://developer.joomla.org/security-centre/664-20161201-core-elevated-privileges.html
URL https://developer.joomla.org/security-centre/665-20161202-core-shell-upload.html
URL https://developer.joomla.org/security-centre/666-20161203-core-information-disclosure.html
URL https://www.joomla.org/announcements/release-news/5693-joomla-3-6-5-released.html