CVE-2016-8870
moderate-risk
Published 2016-11-04
The register method in the UsersModelRegistration class in controllers/user.php in the Users component in Joomla! before 3.6.4, when registration has been disabled, allows remote attackers to create user accounts by leveraging failure to check the Allow User Registration configuration setting.
Do I need to act?
!
91.5% chance of exploitation in next 30 days
EPSS score — higher than 8% of all CVEs
-
Not on CISA KEV list
No confirmed active exploitation reported to CISA
!
1 public exploit available
?
Patch status unknown
Check vendor advisories for fix availability and mitigation guidance
8
CVSS 8.1/10
High
NETWORK
/ HIGH complexity
Affected Products (1)
Affected Vendors
References (18)
Third Party Advisory
http://www.rapid7.com/db/modules/auxiliary/admin/http/joomla_registration_prives...
Third Party Advisory
http://www.securityfocus.com/bid/93876
Third Party Advisory
http://www.securitytracker.com/id/1037108
Third Party Advisory
http://www.rapid7.com/db/modules/auxiliary/admin/http/joomla_registration_prives...
Third Party Advisory
http://www.securityfocus.com/bid/93876
Third Party Advisory
http://www.securitytracker.com/id/1037108
49
/ 100
moderate-risk
Severity
24/34 · High
Exploitability
20/34 · Moderate
Exposure
5/34 · Minimal