What the vulnerability does
01Description
An improper access check allows privelege escalation through the com_users group editing webservice endpoint.
CVSS base score
CVSS vector
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N
What the vulnerability does
An improper access check allows privelege escalation through the com_users group editing webservice endpoint.
Explanation of Vulnerability in Simple Terms
Joomla! CMS versions 4.0.0 through 5.4.5 contain an access control flaw that allows unauthenticated attackers to modify site data over the network. The vulnerability requires specific timing conditions to exploit but does not require user interaction. Site administrators should update to a version newer than 5.4.5 to remediate this issue.
What an attacker can do
Modify site data without authentication by sending network requests under specific timing conditions.
Potential impact on your site
Attackers can alter site content, settings, or data without logging in, potentially compromising site integrity and user trust.
Conditions required to exploit
Network access to the Joomla site; no authentication or user interaction required, but exploitation requires precise timing.
Key dates
External resources
Related vulnerabilities