Softpedia
 

NEWS CATEGORIES:



NEWS ARCHIVE >>
SOFTPEDIA REVIEWS >>
MEET THE EDITORS >>
Home > News > Editor Blogs > Security

November 16th, 2011, 11:26 GMT · By Eduard Kovacs

BLOG

High-Risk Password Change Vulnerability Fixed in Joomla! 1.7.3

SHARE:

Adjust text size:

The latest Joomla comes with two major security updates Enlarge picture - The latest Joomla comes with two major security updates
Previous versions of Joomla!, the popular open source CMS, contained flaws that could allow an attacker to change a user's password and even launch cross-site scripting attacks.

The 1.5.x, 1.6.x and the 1.7.x variants were affected by the security holes that could have presented real risks to users.

Joomla! 1.5.24 and earlier 1.5 versions presented a weak random number generation during the password reset process, fact which could have allowed a cybercriminal to change a user's password.

Besides this issue, 1.7.2 and all earlier 1.7.x and 1.6.x versions had an XSS vulnerability in the back end due to an inadequate filtering.

The latest update also comes with fixes for more than 70 bugs that are non-security related.

Joomla! 1.7.3 / 1.6.6 / 1.5.25 / 1.0.15 is available for download here
FILED UNDER:
Joomla
CMS
security update

TELL US WHAT YOU THINK:

1,123 hits · Link to this article · Print article · Send to friend · Subscribe to news

MUST-READ RELATED ARTICLES:


Symphony CMS Vulnerable to XSS and SQL Injection Attacks

ESET Nod32 Blocks Facebook Image Attachments

Apple Fixes Man-in-the-Middle Issue in iTunes 10.5.1

Patched Adobe Flash SWF Vulnerability Still Makes Victims

Adobe Rolls Out Security Updates with Flash Player 11.1

READER COMMENTS:



No user comments yet.
Be the first to express your opinion!
Copyright © 2001-2012 Softpedia. Contact/Tip us at

WindowsGamesDriversMacLinuxScriptsMobileHandheldNews

SUBMIT PROGRAM   |   ADVERTISE   |   GET HELP   |   SEND US FEEDBACK   |   RSS FEEDS   |   UPDATE YOUR SOFTWARE   |   ROMANIAN FORUM