目标达成 感谢每一位支持者 — 我们达成了 100% 目标!

目标: 1000 元 · 已筹: 1359 元

100%

CVE-2023-23752— Joomla 安全漏洞

一分钟漏洞结论

影响对象
Joomla! Project Joomla! CMS
利用判断
已确认在野利用,应立即处置
建议动作
优先检查厂商安全公告和参考链接中的修复版本;无法立即升级时,限制受影响服务暴露并加强监测。

Joomla是美国Open Source Matters团队的一套使用PHP和MySQL开发的开源、跨平台的内容管理系统(CMS)。 Joomla 4.0.0版本至4.2.7版本存在安全漏洞,该漏洞源于不正确的访问检查,允许对web服务端点进行未经授权的访问。

AI 预测 7.5 利用难度: 较易 KEV EPSS 99.83% · P100
获取后续新漏洞提醒 登录后订阅

一、 漏洞 CVE-2023-23752 基础信息

漏洞信息

对漏洞内容有疑问?看看神龙的深度分析是否有帮助!
查看神龙十问 ↗

尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。

Vulnerability Title
[20230201] - Core - Improper access check in webservice endpoints
来源: CVE Program / CVE List V5
Vulnerability Description
An issue was discovered in Joomla! 4.0.0 through 4.2.7. An improper access check allows unauthorized access to webservice endpoints.
来源: CVE Program / CVE List V5
CVSS Information
N/A
来源: CVE Program / CVE List V5
Vulnerability Type
N/A
来源: CVE Program / CVE List V5
Vulnerability Title
Joomla 安全漏洞
来源: 中国国家信息安全漏洞库 CNNVD
Vulnerability Description
Joomla是美国Open Source Matters团队的一套使用PHP和MySQL开发的开源、跨平台的内容管理系统(CMS)。 Joomla 4.0.0版本至4.2.7版本存在安全漏洞,该漏洞源于不正确的访问检查,允许对web服务端点进行未经授权的访问。
来源: 中国国家信息安全漏洞库 CNNVD
CVSS Information
N/A
来源: 中国国家信息安全漏洞库 CNNVD
Vulnerability Type
N/A
来源: 中国国家信息安全漏洞库 CNNVD

神龙十问 — AI 深度分析

十问解析:根本原因、利用方式、修复建议、紧迫性。摘要免费,完整版需登录。

受影响产品

厂商 产品 影响版本 CPE 订阅
Joomla! Project Joomla! CMS 4.0.0-4.2.7 -

二、漏洞 CVE-2023-23752 的公开POC

# POC 描述 源链接 神龙链接
1 Joomla! 未授权访问漏洞 https://github.com/YusinoMy/CVE-2023-23752 POC详情
2 CVE-2023-23752 nuclei template https://github.com/Saboor-Hakimi/CVE-2023-23752 POC详情
3 PoC for CVE-2023-23752 (joomla CMS) https://github.com/WhiteOwl-Pub/CVE-2023-23752 POC详情
4 Joomla! 4.0.0 through 4.2.7. An improper access check allows unauthorized access to webservice endpoints. https://github.com/Vulnmachines/joomla_CVE-2023-23752 POC详情
5 CVE-2023-23752 poc https://github.com/wangking1/CVE-2023-23752-poc POC详情
6 未授权访问漏洞 https://github.com/ibaiw/joomla_CVE-2023-23752 POC详情
7 CVE-2023-23752 Joomla 未授权访问漏洞 poc https://github.com/ifacker/CVE-2023-23752-Joomla POC详情
8 simple program for joomla CVE-2023-23752 scanner for pentesting and educational purpose https://github.com/z3n70/CVE-2023-23752 POC详情
9 Joomla 未授权访问漏洞 CVE-2023-23752 https://github.com/keyuan15/CVE-2023-23752 POC详情
10 None https://github.com/adriyansyah-mf/CVE-2023-23752 POC详情
11 Mass Checker CVE-2023-23752 https://github.com/haxor1337x/Mass-Checker-CVE-2023-23752 POC详情
12 开源,go多并发批量探测poc,准确率高 https://github.com/GhostToKnow/CVE-2023-23752 POC详情
13 Bulk scanner + get config from CVE-2023-23752 https://github.com/gibran-abdillah/CVE-2023-23752 POC详情
14 An issue was discovered in Joomla! 4.0.0 through 4.2.7. An improper access check allows unauthorized access to webservice endpoints. https://github.com/H454NSec/CVE-2023-23752 POC详情
15 python 2.7 https://github.com/Jenderal92/Joomla-CVE-2023-23752 POC详情
16 Joomla! < 4.2.8 - Unauthenticated information disclosure https://github.com/Acceis/exploit-CVE-2023-23752 POC详情
17 Joomla Unauthorized Access Vulnerability (CVE-2023-23752) Dockerized https://github.com/karthikuj/CVE-2023-23752-Docker POC详情
18 None https://github.com/0xNahim/CVE-2023-23752 POC详情
19 Poc for CVE-2023-23752 https://github.com/adhikara13/CVE-2023-23752 POC详情
20 CVE-2023-23752 https://github.com/AkbarWiraN/Joomla-Scanner POC详情
21 Perform With Mass Exploiter In Joomla 4.2.8. https://github.com/ThatNotEasy/CVE-2023-23752 POC详情
22 None https://github.com/wibuheker/Joomla-CVE-2023-23752 POC详情
23 Joomla未授权访问漏洞 https://github.com/Sweelg/CVE-2023-23752 POC详情
24 simple program for joomla scanner CVE-2023-23752 with target list https://github.com/MrP4nda1337/CVE-2023-23752 POC详情
25 Mass CVE-2023-23752 scanner https://github.com/k0valskia/CVE-2023-23752 POC详情
26 None https://github.com/yTxZx/CVE-2023-23752 POC详情
27 Joomla Unauthenticated Information Disclosure (CVE-2023-23752) exploit https://github.com/AlissoftCodes/CVE-2023-23752 POC详情
28 Exploit for CVE-2023-23752 (4.0.0 <= Joomla <= 4.2.7). https://github.com/Pushkarup/CVE-2023-23752 POC详情
29 Joomla Unauthorized Access Vulnerability https://github.com/cybernetwiz/CVE-2023-23752 POC详情
30 CVE-2023-23752 https://github.com/Youns92/Joomla-v4.2.8---CVE-2023-23752 POC详情
AI 生成 POC 高级

未找到公开 POC。

登录以生成 AI POC

三、漏洞 CVE-2023-23752 的情报信息

请登录查看更多情报信息。

CVE-2023-23752 其他参考 (1)

IV. Related Vulnerabilities

V. Comments for CVE-2023-23752

暂无评论


发表评论