CVE-2016-8869
CRITICAL 9.8EPSS 97.2%
The register method in the UsersModelRegistration class in controllers/user.php in the Users component in Joomla! before 3.6.4 allows remote attackers to gain privileges by leveraging incorrect use of unfiltered data when registering on a site.
- CVSS v3.0
- 9.8 CRITICAL
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H - CVSS v2.0
- 7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P - EPSS
- 97.24% chance of exploitation in the next 30 days, 100th percentile
- Published
- 2016-11-04
- Updated
- 2024-08-06
Proof-of-concept exploits (5)
- https://medium.com/%40showthread/joomla-3-6-4-account-creation-elevated-privileges-write-…
- cved-sources/cve-2016-88690★ · 2021-04-15
- rustyJ4ck/JoomlaCVE201688697★ · 2016-11-10
- sunsunza2009/Joomla-3.4.4-3.6.4_CVE-2016-8869_and_CVE-2016-88700★ · 2016-11-02
- zugetor/Joomla-3.4.4-3.6.4_CVE-2016-8869_and_CVE-2016-88700★ · 2016-11-02