MEDIUM
CVE-2023-23752
CVSS
5.3
KEV
Description
An issue was discovered in Joomla! 4.0.0 through 4.2.7. An improper access check allows unauthorized access to webservice endpoints.
Summary dbcve.org
Joomla! 4.0.0 through 4.2.7 contains an improper access control vulnerability where webservice endpoints lack proper authorization checks, allowing unauthenticated or unauthorized users to access sensitive API functionality that should be restricted.
Mitigation
Upgrade to Joomla! 4.2.8 or later which contains the proper access control fixes for all webservice endpoints.
Weakness (CWE)
CWE-284
Improper Access Control
EPSS Score
99.83%
Probability of exploitation in next 30 days
100th percentile
References
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.