module
Joomla API Improper Access Checks
| Disclosed | Created |
|---|---|
| Feb 1, 2023 | Apr 21, 2023 |
Disclosed
Feb 1, 2023
Created
Apr 21, 2023
Description
Joomla versions between 4.0.0 and 4.2.7, inclusive, contain an improper API access vulnerability.
This vulnerability allows unauthenticated users access to webservice endpoints which contain
sensitive information. Specifically for this module we exploit the users and config/application
endpoints.
This module was tested against Joomla 4.2.7 running on Docker.
This vulnerability allows unauthenticated users access to webservice endpoints which contain
sensitive information. Specifically for this module we exploit the users and config/application
endpoints.
This module was tested against Joomla 4.2.7 running on Docker.
Authors
h00die
Tianji Lab
Tianji Lab
References
Module Options
To display the available options, load the module within the Metasploit console and run the commands 'show options' or 'show advanced':
Rapid7 Labs
2026 Global Threat Landscape Report
The predictive window has collapsed. Exploitation follows disclosure in days. See how attackers are accelerating and how to stay ahead.