CVE-2016-8870
HIGH 8.1EPSS 81.2%
The register method in the UsersModelRegistration class in controllers/user.php in the Users component in Joomla! before 3.6.4, when registration has been disabled, allows remote attackers to create user accounts by leveraging failure to check the Allow User Registration configuration setting.
- CVSS v3.0
- 8.1 HIGH
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H - CVSS v2.0
- 6.8 MEDIUM
AV:N/AC:M/Au:N/C:P/I:P/A:P - EPSS
- 81.21% chance of exploitation in the next 30 days, 100th percentile
- Published
- 2016-11-04
- Updated
- 2024-08-06
Proof-of-concept exploits (5)
- https://medium.com/%40showthread/joomla-3-6-4-account-creation-elevated-privileges-write-…
- cved-sources/cve-2016-88700★ · 2021-04-15
- rustyJ4ck/JoomlaCVE201688697★ · 2016-11-10
- sunsunza2009/Joomla-3.4.4-3.6.4_CVE-2016-8869_and_CVE-2016-88700★ · 2016-11-02
- zugetor/Joomla-3.4.4-3.6.4_CVE-2016-8869_and_CVE-2016-88700★ · 2016-11-02