MEDIUM
GHSA-mxr8-pcpg-m23j
Joomla! doesn't configure .htaccess to apply certain security checks that "block common exploits" to SEF URLs
Quick fix
GHSA-mxr8-pcpg-m23j — joomla/joomla-platform: upgrade to the fixed version with the command below.
composer require joomla/joomla-platform:^1.5.4Details
Joomla! before 1.5.4 does not configure .htaccess to apply certain security checks that "block common exploits" to SEF URLs, which has unknown impact and remote attack vectors.
Are you affected?
Enter the version of the package you're using.
Affected packages
Packagist/joomla/joomla-platform
Introduced in:
0Fixed in: 1.5.4Fix
composer require joomla/joomla-platform:^1.5.4References
- https://nvd.nist.gov/vuln/detail/CVE-2008-3228[ADVISORY]
- https://exchange.xforce.ibmcloud.com/vulnerabilities/44206[WEB]
- https://github.com/joomla/joomla-platform[PACKAGE]
- https://web.archive.org/web/20080730154423/http://www.joomla.org/content/view/5180/1[WEB]
- http://www.joomla.org/content/view/5180/1/1/1/#htaccess[WEB]
- http://www.openwall.com/lists/oss-security/2008/07/12/2[WEB]