Description
Joomla! Core is prone to multiple vulnerabilities, including security bypass and open redirect vulnerabilities. Exploiting these issues may allow attackers to perform otherwise restricted actions and subsequently bypass improperly configured .htaccess security checks, access administration area, access cached pages or to redirect users to arbitrary web sites and conduct phishing attacks; other attacks are also possible. Joomla! Core versions 1.5.x ranging from 1.5.0 and up to and including 1.5.3 are vulnerable.
Remediation
Update to Joomla! Core version 1.5.4 or latest
References
Related Vulnerabilities
Apache Tomcat Permissions, Privileges, and Access Controls Vulnerability (CVE-2016-0762)
WordPress Plugin Mingle Forum Multiple Cross-Site Scripting Vulnerabilities (1.0.33)
Plone CMS Improper Restriction of XML External Entity Reference Vulnerability (CVE-2020-28734)
Oracle HTTP Server Server-Side Request Forgery (SSRF) Vulnerability (CVE-2021-40438)
WordPress Plugin Zoho CRM Lead Magnet Unspecified Vulnerability (1.7.2.9)