Joomla! -- multiple vulnerabilities

Affected packages
1.6.0 <= joomla3 < 3.6.5


VuXML ID 624b45c0-c7f3-11e6-ae1b-002590263bf5
Discovery 2016-12-06
Entry 2016-12-22

The JSST and the Joomla! Security Center report:

[20161201] - Core - Elevated Privileges

Incorrect use of unfiltered data stored to the session on a form validation failure allows for existing user accounts to be modified; to include resetting their username, password, and user group assignments.

[20161202] - Core - Shell Upload

Inadequate filesystem checks allowed files with alternative PHP file extensions to be uploaded.

[20161203] - Core - Information Disclosure

Inadequate ACL checks in the Beez3 com_content article layout override enables a user to view restricted content.


CVE Name CVE-2016-9836
CVE Name CVE-2016-9837
CVE Name CVE-2016-9838