JOOMLA! Update to the latest version or you could be hacked!

Joomla hacked again! According to reports, the vulnerability could pose a severe risk to thousands of websites worldwide.

miércoles, 16 de octubre de 2019 • 1 min read • Q2BSTUDIO Team

joomla-hacking-vulnerability-risk-cybersecurity

A vulnerability analysis specialist has just revealed a zero-day vulnerability in versions of Joomla!, the popular content management system (CMS) released between September 2012 and December 2015. According to reports, the vulnerability could pose a severe risk to thousands of websites worldwide.

This flaw may seem too old, but in the case of Joomla! this could be irrelevant, as most website administrators using this CMS do not usually update the software for various reasons, mainly due to compatibility issues that many plugins present when updating this system.

According to vulnerability analysis specialists, exploiting this vulnerability is really simple for an average hacker, as it only requires a PHP code injection on the CMS homepage for the threat actor to be able to execute remote code on the server.

A broader report, published on the specialized platform ZDNet, mentions that this vulnerability is very similar to the flaw identified as CVE-2015-8562, discovered in 2015. At that time, the vulnerability caused serious problems on thousands of websites worldwide.

However, there is a determining difference between the two flaws. The recently discovered zero-day vulnerability only affects versions of the 3.x branch, while CVE-2015-8562 affected all versions of Joomla! from 1.5x onwards, so the scope of the new flaw is much smaller.

Joomla! has already been notified and the security patch for this flaw appears to be available. However, as already mentioned, it could be complicated for all Joomla! website administrators to decide to update their implementations promptly.

OUR SERVICES

How we can help you

Do you have a project in mind?

Tell us your vision and we'll turn it into a software solution. Whatever the scope, we make your idea real.