PoC Index

CVE-2016-8870

HIGH 8.1EPSS 81.2%

The register method in the UsersModelRegistration class in controllers/user.php in the Users component in Joomla! before 3.6.4, when registration has been disabled, allows remote attackers to create user accounts by leveraging failure to check the Allow User Registration configuration setting.

CVSS v3.0
8.1 HIGHCVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS v2.0
6.8 MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
EPSS
81.21% chance of exploitation in the next 30 days, 100th percentile
Published
2016-11-04
Updated
2024-08-06

Proof-of-concept exploits (5)

ExploitDB entries (1)

References

Related