Description
Joomla! 1.6.x/1.7.x/2.5.0-2.5.2 suffers from a privilege escalation vulnerability that allows users to be registered into any group not having 'core.admin' privileges.
Remediation
Joomla! versions 1.0.x, 1.5.x, and 2.5.3+ are not vulnerable. No patch has been issued for 1.6.x or 1.7.x and users of these versions are strongly urged to upgrade to 2.5.3 immediately.
References
Related Vulnerabilities
WordPress Plugin Sendit WP Newsletter 'submit.php' Blind SQL Injection (1.5.9)
WordPress Plugin I Recommend This SQL Injection (3.7.2)
WordPress Plugin Tune Library SQL Injection (1.5.4)
WordPress Plugin Responsive Slider-Image Slider-Slideshow for WordPress SQL Injection (2.8.6)
WordPress Plugin Slider Hero with Animation, Video Background SQL Injection (8.2.6)