CVE-2016-8870
82Vexday Risk Score
Patch now. It exploitation observed by VulnCheck and has a working public exploit.
ssvc Actepss 81%
from disclosure to weapon0 days
Published on NVDNov 4
1st PoCOct 27
metasploitOct 25
VulnCheckOct 28
exploitation probability
81%top 1% of all CVEs
observed exploitation
yesVulnCheck
3 public exploit(s)
The register method in the UsersModelRegistration class in controllers/user.php in the Users component in Joomla! before 3.6.4, when registration has been disabled, allows remote attackers to create user accounts by leveraging failure to check the Allow User Registration configuration setting.
Affected products
n/a · n/apublic PoCs found — 3
exploitdbwww.exploit-db.com/exploits/40637unverifiedgithubgithub.com/cved-sources/cve-2016-8870★ 0cve_referencewww.exploit-db.com/exploits/40637/unverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.
References
https://blog.sucuri.net/2016/10/details-on-the-privilege-escalation-vulnerability-in-joomla.htmlhttps://developer.joomla.org/security-centre/659-20161001-core-account-creation.htmlhttps://github.com/joomla/joomla-cms/commit/bae1d43938c878480cfd73671e4945211538fdcfhttps://medium.com/%40showthread/joomla-3-6-4-account-creation-elevated-privileges-write-up-and-exploit-965d8fb46fa2#.rq4qh1v4rhttps://www.exploit-db.com/exploits/40637/http://www.rapid7.com/db/modules/auxiliary/admin/http/joomla_registration_priveschttp://www.securityfocus.com/bid/93876http://www.securitytracker.com/id/1037107http://www.securitytracker.com/id/1037108