Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2023-23752— [20230201] - Core - Improper access check in webservice endpoints

Quick assessment

Affected
Joomla! Project Joomla! CMS
Exploitation
Confirmed exploitation in the wild; remediate immediately
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Joomla是美国Open Source Matters团队的一套使用PHP和MySQL开发的开源、跨平台的内容管理系统(CMS)。 Joomla 4.0.0版本至4.2.7版本存在安全漏洞,该漏洞源于不正确的访问检查,允许对web服务端点进行未经授权的访问。

AI Predicted 7.5 Difficulty: Easy KEV EPSS 99.83% · P100
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2023-23752

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
[20230201] - Core - Improper access check in webservice endpoints
Source: CVE Program / CVE List V5
Vulnerability Description
An issue was discovered in Joomla! 4.0.0 through 4.2.7. An improper access check allows unauthorized access to webservice endpoints.
Source: CVE Program / CVE List V5
CVSS Information
N/A
Source: CVE Program / CVE List V5
Vulnerability Type
N/A
Source: CVE Program / CVE List V5
Vulnerability Title
Joomla 安全漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Joomla是美国Open Source Matters团队的一套使用PHP和MySQL开发的开源、跨平台的内容管理系统(CMS)。 Joomla 4.0.0版本至4.2.7版本存在安全漏洞,该漏洞源于不正确的访问检查,允许对web服务端点进行未经授权的访问。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Shenlong Deep Dive — AI Deep Analysis

10-question deep dive: root cause, exploitation, mitigation, urgency. Read summary free, full version requires login.

Affected Products

Vendor Product Affected Versions CPE Subscribe
Joomla! Project Joomla! CMS 4.0.0-4.2.7 -

II. Public POCs for CVE-2023-23752

# POC Description Source Link Shenlong Link
1 Joomla! 未授权访问漏洞 https://github.com/YusinoMy/CVE-2023-23752 POC Details
2 CVE-2023-23752 nuclei template https://github.com/Saboor-Hakimi/CVE-2023-23752 POC Details
3 PoC for CVE-2023-23752 (joomla CMS) https://github.com/WhiteOwl-Pub/CVE-2023-23752 POC Details
4 Joomla! 4.0.0 through 4.2.7. An improper access check allows unauthorized access to webservice endpoints. https://github.com/Vulnmachines/joomla_CVE-2023-23752 POC Details
5 CVE-2023-23752 poc https://github.com/wangking1/CVE-2023-23752-poc POC Details
6 未授权访问漏洞 https://github.com/ibaiw/joomla_CVE-2023-23752 POC Details
7 CVE-2023-23752 Joomla 未授权访问漏洞 poc https://github.com/ifacker/CVE-2023-23752-Joomla POC Details
8 simple program for joomla CVE-2023-23752 scanner for pentesting and educational purpose https://github.com/z3n70/CVE-2023-23752 POC Details
9 Joomla 未授权访问漏洞 CVE-2023-23752 https://github.com/keyuan15/CVE-2023-23752 POC Details
10 None https://github.com/adriyansyah-mf/CVE-2023-23752 POC Details
11 Mass Checker CVE-2023-23752 https://github.com/haxor1337x/Mass-Checker-CVE-2023-23752 POC Details
12 开源,go多并发批量探测poc,准确率高 https://github.com/GhostToKnow/CVE-2023-23752 POC Details
13 Bulk scanner + get config from CVE-2023-23752 https://github.com/gibran-abdillah/CVE-2023-23752 POC Details
14 An issue was discovered in Joomla! 4.0.0 through 4.2.7. An improper access check allows unauthorized access to webservice endpoints. https://github.com/H454NSec/CVE-2023-23752 POC Details
15 python 2.7 https://github.com/Jenderal92/Joomla-CVE-2023-23752 POC Details
16 Joomla! < 4.2.8 - Unauthenticated information disclosure https://github.com/Acceis/exploit-CVE-2023-23752 POC Details
17 Joomla Unauthorized Access Vulnerability (CVE-2023-23752) Dockerized https://github.com/karthikuj/CVE-2023-23752-Docker POC Details
18 None https://github.com/0xNahim/CVE-2023-23752 POC Details
19 Poc for CVE-2023-23752 https://github.com/adhikara13/CVE-2023-23752 POC Details
20 CVE-2023-23752 https://github.com/AkbarWiraN/Joomla-Scanner POC Details
21 Perform With Mass Exploiter In Joomla 4.2.8. https://github.com/ThatNotEasy/CVE-2023-23752 POC Details
22 None https://github.com/wibuheker/Joomla-CVE-2023-23752 POC Details
23 Joomla未授权访问漏洞 https://github.com/Sweelg/CVE-2023-23752 POC Details
24 simple program for joomla scanner CVE-2023-23752 with target list https://github.com/MrP4nda1337/CVE-2023-23752 POC Details
25 Mass CVE-2023-23752 scanner https://github.com/k0valskia/CVE-2023-23752 POC Details
26 None https://github.com/yTxZx/CVE-2023-23752 POC Details
27 Joomla Unauthenticated Information Disclosure (CVE-2023-23752) exploit https://github.com/AlissoftCodes/CVE-2023-23752 POC Details
28 Exploit for CVE-2023-23752 (4.0.0 <= Joomla <= 4.2.7). https://github.com/Pushkarup/CVE-2023-23752 POC Details
29 Joomla Unauthorized Access Vulnerability https://github.com/cybernetwiz/CVE-2023-23752 POC Details
30 CVE-2023-23752 https://github.com/Youns92/Joomla-v4.2.8---CVE-2023-23752 POC Details
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2023-23752

请登录查看更多情报信息。

Other References for CVE-2023-23752 (1)

IV. Related Vulnerabilities

V. Comments for CVE-2023-23752

No comments yet


Leave a comment