CVE-2023-23752 is an improper access check vulnerability in Joomla! versions 4.0.0 through 4.2.7, allowing unauthorized access to webservice endpoints. It carries a CVSS score of 5.3 (Medium) due to its network-based attack vector and low complexity, potentially leading to information disclosure. This vulnerability is actively exploited in the wild, with public exploit code available in Metasploit, Nuclei templates, and ExploitDB, and has garnered significant community discussion and media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 4.0.0, < 4.2.8CPE matchmatch criteria | cpe:2.3:a:joomla:joomla\!:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.