Joomla! "Clickjacking" Security Bypass Vulnerability

SECUNIA ADVISORY ID:
SA51187

VERIFY ADVISORY:
Secunia.com
http://secunia.com/advisories/51187/
Customer Area (Credentials Required)
https://ca.secunia.com/?page=viewadvisory&vuln_id=51187

RELEASE DATE:
2012-11-09
DESCRIPTION:
A vulnerability has been reported in Joomla!, which can be exploited
by malicious people to bypass certain security restrictions and
conduct cross-site request forgery attacks.

The application allows users to perform certain actions via HTTP
requests without performing any validity checks to verify the
requests. This can be exploited to perform certain unspecified
actions by tricking a user into clicking a specially crafted link via
clickjacking.

The vulnerability is reported in versions 2.5.7 and prior.

SOLUTION:
Update to version 2.5.8.

PROVIDED AND/OR DISCOVERED BY:
The vendor credits Ajay Singh Negi.

ORIGINAL ADVISORY:
http://developer.joomla.org/security/news/544-20121102-core-clickjacking.html

RECENT ARTICLE

RECENT POST