Joomla!
CVE-2023-23752
Last updated
CVE-2023-23752
Last updated
On February 16, 2023, Joomla! published a security advisory for CVE-2023-23752. The advisory describes an “improper access check” affecting Joomla! 4.0.0 through 4.2.7. The following day, a chinese-language blog shared the technical details of the vulnerability. The blog describes an authentication bypass that allows an attacker to leak privileged information. If an attacker can log into the Joomla! administrative web interface, as the Super User, the attacker has easy path to execute arbitrary code.
For Information Disclosure, run the following command.
For RCE, run the following steps. Save it after you modify the index.php template.