SB2017092009 - Multiple vulnerabilities in Joomla!
Published: September 20, 2017
Security Bulletin ID
SB2017092009
Severity
Medium
Patch available
YES
Number of vulnerabilities
2
Exploitation vector
Remote access
Highest impact
Information disclosure
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 2 secuirty vulnerabilities.
1) Information disclosure (CVE-ID: CVE-2017-14595)
The vulnerability allows a remote attacker to obtain potentially sensitive information.The vulnerability exists due to a logical error in SQL query. A remote attacker can read article intro texts when these articles are in the archived state.
2) Sensitive information disclosure (CVE-ID: CVE-2017-14596)
The vulnerability allows a remote attacker to obtain user credentials.The vulnerability exists due to improper input sanitization in the LDAP authentication plugin. A remote attacker can gain disclose usernames and passwords.
Remediation
Install update from vendor's website.