Critical ‘Joomla’ bugs leaves 2.8million websites extremely vulnerable

A critical SQL-injection vulnerability in Joomla most widely used content management system; leaves around 2.8 million websites vulnerable to hackers. The bug allow a hacker to get administrative access of the website. Joomla has fixed the vulnerability earlier this week but it has effected e-commerce and other sensitive industries for over 2 years.

Joomla 3.4.5  an updated version has been released this week; which has fixed three very critical reported vulnerabilities. The issues fixed in the new update are as under:

  • High Priority – Core – SQL Injection (affecting Joomla 3.2 through 3.4.4). 
  • Medium Priority – Core – ACL Violations (affecting Joomla 3.2 through 3.4.4).
  • Medium Priority – Core – ACL Violations (affecting Joomla 3.0 through 3.4.4).


The bug was first reported to Joomla by the Trustwave spiderlab researcher “Asaf Orpani” he discovered the most severe vulnerability of them all; SQL Injection vulnerability (in versions 3.2 and 3.4.4) . The researcher has gained the full admin access of the Joomla powered sites by exploiting vulnerability; while admistrator was logged into the website powered by Joomla. 
Since Joomla was a popular used opensource content management system; used all over the world. Joomla immediately releases the version, 3.4.5 which the researcher believe is bug free. So, the administrators who are using Joomla should immediately install the new patch to avoid any attack on their website. 

SQL-injection vulnerabilities allow end users to execute powerful commands on a website’s backend database by entering specialized text in search boxes or other input fields found on a webpage. The flaws, which are among the most commonly exploited website vulnerabilities, are the result of an insecure Web application failing to enforce the treatment of incoming data as plaintext rather than executable code. Often, this makes it possible for hackers to download confidential files from the vulnerable server.

Ehacking Staff
With more than 50 global partners, we are proud to count the world’s leading cybersecurity training provider. EH Academy is the brainchild of Ehacking, which has been involved in the field of training since the past Five years and continues to help in creating professional IT experts.

Most Popular

Top Suggestions To Minimize Cyber Attack Risks

The Cyber Protection and Cyber Attack definition play an important role in maintaining both global security and operational productivity due to the rapid proliferation...

Policing the Dark Web (TOR): How Authorities track People on Darknet

The darknet, especially the TOR network, can be hacked, or the information of the people using it can be extracted in the plain text....

Best VPNs for Android – and Why You Need One Now

Most people protect their laptops and computers from potential cyber-attacks but only consider the cybersecurity of their mobile devices when it’s too late. In recent...

The Levels of the Internet Surface Web, Deep Web, and Dark Web

The internet, invented by Vinton Cerf and Bob Cahn, has evolved since its creation in the 1960s. In 1990, the World Wide Web transformed...

LOOKING FOR HACKING RECIPES FORM THE PRO?

Then sign up for FREE to the ehacking’s exclusive group. You will get the exclusive tips/tricks, tutorials, webinars & courses that I ONLY share with my fellow on this exclusive newsletter.