Description
Joomla versions between 4.0.0 and 4.2.7, inclusive, contain an improper API access vulnerability. This vulnerability allows unauthenticated users access to webservice endpoints which contain sensitive information. Specifically for this module we exploit the users and config/application endpoints.
This module was tested against Joomla 4.2.7 running on Docker.
Module options
To display the available options, load the module within the Metasploit console and run the commands 'show options' or 'show advanced':
msf > use auxiliary/scanner/http/joomla/api_improper_access_checksmsf undefined(api_improper_access_checks) > show actions ...actions...msf undefined(api_improper_access_checks) > set ACTION < action-name >msf undefined(api_improper_access_checks) > show options ...show and set options...msf undefined(api_improper_access_checks) > runPrioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub