MEDIUM
GHSA-9qr2-fx2g-pfvh
Joomla! Open Redirect vulnerability
Quick fix
GHSA-9qr2-fx2g-pfvh — joomla/framework: upgrade to the fixed version with the command below.
composer require joomla/framework:^1.5.7Details
Multiple open redirect vulnerabilities in Joomla! 1.5 before 1.5.7 allow remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a "passed in" URL.
Are you affected?
Enter the version of the package you're using.
Affected packages
Packagist/joomla/framework
Introduced in:
1.5.0Fixed in: 1.5.7Fix
composer require joomla/framework:^1.5.7References
- https://nvd.nist.gov/vuln/detail/CVE-2008-4104[ADVISORY]
- https://exchange.xforce.ibmcloud.com/vulnerabilities/45071[WEB]
- https://github.com/joomla/joomla-framework[PACKAGE]
- https://web.archive.org/web/20081219152017/http://developer.joomla.org/security/news/274-20080904-core-redirect-spam.html[WEB]
- http://marc.info/?l=oss-security&m=122115344915232&w=2[WEB]
- http://marc.info/?l=oss-security&m=122118210029084&w=2[WEB]
- http://marc.info/?l=oss-security&m=122152798516853&w=2[WEB]
- http://securityreason.com/securityalert/4275[WEB]