Joomla! 2.5.0 < 3.9.3 Multiple Vulnerabilities

critical Nessus Plugin ID 122346

Synopsis

The remote web server contains a PHP application that is affected by multiple vulnerabilities.

Description

According to its self-reported version number, the Joomla! installation running on the remote web server is prior to 3.9.3. It is, therefore, affected by multiple vulnerabilities:

- An object injection vulnerability exists in Joomla! prior to 3.9.3 due to the absence of a protection mechanism to prevent the use of the phar:// handler for non .phar files. An unauthenticated, remote attacker can exploit this to include arbitrary files (CVE-2019-7743).

- A cross-site scripting (XSS) vulnerability exists due to improper validation of user-supplied input before returning it to users. An unauthenticated, remote attacker can exploit this, by convincing a user to click a specially crafted URL, to execute arbitrary script code in a user's browser session (CVE-2019-7740, CVE-2019-7741, CVE-2019-7744).

- An issue exists in Joomla! prior to 3.9.3. The 'No Filtering' textfilter overrides child settings in the Global Configuration.
This is intended behavior. However, it might be unexpected for the user because the configuration dialog lacks an additional message to explain this (CVE-2019-7739).

Note that Nessus has not attempted to exploit these issues but has instead relied only on the application's self-reported version number.

Solution

Upgrade to Joomla! version 3.9.3 or later.

See Also

http://www.nessus.org/u?de138a30

Plugin Details

Severity: Critical

ID: 122346

File Name: joomla_393.nasl

Version: 1.5

Type: remote

Family: CGI abuses

Published: 2/20/2019

Updated: 4/11/2022

Configuration: Enable paranoid mode, Enable thorough checks

Supported Sensors: Nessus

Risk Information

VPR

Risk Factor: Medium

Score: 5.9

CVSS v2

Risk Factor: High

Base Score: 7.5

Temporal Score: 5.5

Vector: CVSS2#AV:N/AC:L/Au:N/C:P/I:P/A:P

CVSS Score Source: CVE-2019-7743

CVSS v3

Risk Factor: Critical

Base Score: 9.8

Temporal Score: 8.5

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

CPE: cpe:/a:joomla:joomla%5c%21

Required KB Items: www/PHP, Settings/ParanoidReport, installed_sw/Joomla!

Exploit Ease: No known exploits are available

Patch Publication Date: 2/12/2019

Vulnerability Publication Date: 1/18/2019

Reference Information

CVE: CVE-2019-7739, CVE-2019-7740, CVE-2019-7741, CVE-2019-7743, CVE-2019-7744

BID: 107015, 107017, 107018, 107020, 107050