Cache Poisoning Vulnerability in Pagination
CVE-2024-27185

9.1CRITICAL

Key Information:

Vendor
Joomla
Vendor
CVE Published:
20 August 2024

Summary

A vulnerability exists in the pagination class of Joomla, allowing attackers to include arbitrary parameters in URLs. This flaw can be exploited to carry out cache poisoning attacks, potentially leading to the delivery of malicious content to users. Proper sanitization and validation measures are essential to protect against such vulnerabilities and ensure the integrity of cached resources.

Affected Version(s)

Joomla! CMS 3.0.0-3.10.16

Joomla! CMS 4.0.0-4.4.6

Joomla! CMS 5.0.0-5.1.2

References

CVSS V3.1

Score:
9.1
Severity:
CRITICAL
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Shane Edwards
.