Improper access control in Joomla! - CVE-2023-23752
Published: February 16, 2023 / Updated: February 21, 2025
Vulnerability identifier: #VU72333
CSH Severity: High
CVSS v4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2023-23752
CWE-ID: CWE-284
Exploitation vector: Remote access
Exploit availability:
The vulnerability is being exploited in the wild
Vulnerability details
The vulnerability allows a remote attacker to compromise the web application.
The vulnerability exists due to improper access restrictions to Web Service endpoints. A remote attacker can bypass implemented security restrictions and compromise the web application.
Affected software
Joomla!
How to mitigate CVE-2023-23752
Install updates from vendor's website.
Joomla! - update to 4.2.8
Links to Public Exploits and PoC-codes
- Exploit #11144 - CVEpedia (Descrição de vulnerabilidades conhecidas, exploits públicos, POC sobre CVE. Feito exclusivamente para fins didáticos e para o conhecimento sobre as falhas reportadas.) (February 21, 2025)
- Exploit #10689 - Joomla! v4.2.8 - Unauthenticated information disclosure (October 25, 2024)
- Exploit #10478 - CVE-2023-23752 () (September 6, 2024)
- Exploit #10415 - CVE-2023-23752 () (August 16, 2024)
- Exploit #10334 - CVE-2023-23752 (Poc for CVE-2023-23752) (August 9, 2024)
- Exploit #10261 - CVE-2023-23752-Joomla-v4.2.8 () (July 26, 2024)
- Exploit #10242 - Joomla-v4.2.8---CVE-2023-23752 (CVE-2023-23752 ) (July 26, 2024)
- Exploit #9994 - CVE-2023-23752 (simple program for joomla CVE-2023-23752 scanner for pentesting and educational purpose) (June 14, 2024)
- Exploit #9817 - CVE-2023-23752 (CVE-2023-23752 Data Extractor) (May 13, 2024)
- Exploit #9792 - CVE-2023-23752 (A simple bash script to exploit Joomla! < 4.2.8 - Unauthenticated information disclosure) (May 13, 2024)
- Exploit #9755 - CVE-2023-23752 (Joomla Unauthenticated Information Disclosure (CVE-2023-23752) exploit) (April 26, 2024)
- Exploit #9568 - CVE-2023-23752-EXPLOIT (A PoC exploit for CVE-2023-23752 - Joomla Improper Access Check in Versions 4.0.0 through 4.2.7) (February 27, 2024)
- Exploit #9554 - CVE-2023-23752 (Joomla! < 4.2.8 - Unauthenticated information disclosure exploit) (February 21, 2024)
- Exploit #9482 - CVE-2023-23752 (Perform With Mass Exploiter In Joomla 4.2.8.) (January 7, 2024)
- Exploit #9432 - CVE-2023-23752 (An access control flaw was identified, potentially leading to unauthorized access to critical webservice endpoints within Joomla! CMS versions 4.0.0 through 4.2.7. This vulnerability could be exploited by attackers to gain unauthorized acc (December 18, 2023)
- Exploit #9014 - CVE-2023-23752 (Perform With Mass Exploiter In Joomla 4.2.8.) (April 27, 2023)
- Exploit #8999 - Joomla API Improper Access Checks (April 21, 2023)
- Exploit #8983 - Radiance (RADIANCE is an exploit for CVE-2023-23752) (April 13, 2023)
- Exploit #8934 - exploit-CVE-2023-23752 (Joomla! < 4.2.8 - Unauthenticated information disclosure) (March 25, 2023)
- Exploit #8899 - CVE-2023-23752 (Bulk scanner + get config from CVE-2023-23752) (March 9, 2023)