Critical ‘Joomla’ bugs leaves 2.8million websites extremely vulnerable

A critical SQL-injection vulnerability in Joomla most widely used content management system; leaves around 2.8 million websites vulnerable to hackers. The bug allow a hacker to get administrative access of the website. Joomla has fixed the vulnerability earlier this week but it has effected e-commerce and other sensitive industries for over 2 years.

Joomla 3.4.5  an updated version has been released this week; which has fixed three very critical reported vulnerabilities. The issues fixed in the new update are as under:

  • High Priority – Core – SQL Injection (affecting Joomla 3.2 through 3.4.4). 
  • Medium Priority – Core – ACL Violations (affecting Joomla 3.2 through 3.4.4).
  • Medium Priority – Core – ACL Violations (affecting Joomla 3.0 through 3.4.4).


The bug was first reported to Joomla by the Trustwave spiderlab researcher “Asaf Orpani” he discovered the most severe vulnerability of them all; SQL Injection vulnerability (in versions 3.2 and 3.4.4) . The researcher has gained the full admin access of the Joomla powered sites by exploiting vulnerability; while admistrator was logged into the website powered by Joomla. 
Since Joomla was a popular used opensource content management system; used all over the world. Joomla immediately releases the version, 3.4.5 which the researcher believe is bug free. So, the administrators who are using Joomla should immediately install the new patch to avoid any attack on their website. 

SQL-injection vulnerabilities allow end users to execute powerful commands on a website’s backend database by entering specialized text in search boxes or other input fields found on a webpage. The flaws, which are among the most commonly exploited website vulnerabilities, are the result of an insecure Web application failing to enforce the treatment of incoming data as plaintext rather than executable code. Often, this makes it possible for hackers to download confidential files from the vulnerable server.

Ehacking Staff
With more than 50 global partners, we are proud to count the world’s leading cybersecurity training provider. EH Academy is the brainchild of Ehacking, which has been involved in the field of training since the past Five years and continues to help in creating professional IT experts.

Most Popular

OSINT WIFI Tutorial: Track People using WiFi via Wigle

Due to the drastic growth of internet access, Wi-fi networks have become progressively popular. Wi-fi technologies link to the network topologies allows users to...

Why Attack Surface Analysis is a Core of Cybersecurity?

The pandemic of COVID-19 has changed the world dramatically. Almost all everyday actions have gone online: people work from home, students attend lectures through...

The Attack Surface Mapping guide for Ethical Hackers

This article explains how to map the attack surface in a precise and realistic way. An attack surface aims to figure out which areas...

Addressing Myths About Online Casinos & Security

Many people carry a perception that online casinos inherently involve a security risk. The sense is that these sites can be somehow “sketchy” or...