Posted by: notictech | August 20, 2008

Joomla! Password Reset Vulnerability

The Joomla! Project has released an advisory to address a password reset vulnerability in the Joomla! content management system. This vulnerability, which may allow non-validating tokens to be forged, is
due to a flaw in the reset token validation mechanism. Exploitation of this vulnerability may allow an unauthenticated attacker to reset the password of the first enabled user, which is typically an
administrator user.

From: US-CERT


Leave a response

Your response:

Categories