← back
CVE-2016-8869observed exploitation

CVE-2016-8869

82Vexday Risk Score

Patch now. It exploitation observed by VulnCheck and has a working public exploit.

ssvc Actepss 97%
from disclosure to weapon0 days
Published on NVDNov 4
1st PoCOct 27
metasploitOct 25
VulnCheckOct 28
exploitation probability
97%top 1% of all CVEs
observed exploitation
yesVulnCheck
5 public exploit(s)
The register method in the UsersModelRegistration class in controllers/user.php in the Users component in Joomla! before 3.6.4 allows remote attackers to gain privileges by leveraging incorrect use of unfiltered data when registering on a site.
Affected products
n/a · n/a
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.