VYPR
High severity8.1NVD Advisory· Published Nov 4, 2016· Updated May 6, 2026

CVE-2016-8870

CVE-2016-8870

Description

The register method in the UsersModelRegistration class in controllers/user.php in the Users component in Joomla! before 3.6.4, when registration has been disabled, allows remote attackers to create user accounts by leveraging failure to check the Allow User Registration configuration setting.

Affected products

1
  • cpe:2.3:a:joomla:joomla\!:*:*:*:*:*:*:*:*
    Range: <=3.6.3

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

9

News mentions

0

No linked articles in our index yet.