VYPR
High severity7.2NVD Advisory· Published Oct 9, 2018· Updated Jun 17, 2026

CVE-2018-17856

CVE-2018-17856

Description

An issue was discovered in Joomla! before 3.8.13. com_joomlaupdate allows the execution of arbitrary code. The default ACL config enabled the ability of Administrator-level users to access com_joomlaupdate and trigger code execution.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
joomla/frameworkPackagist
>= 2.5.4, < 3.8.133.8.13

Affected products

1

Patches

Vulnerability mechanics

References

7

News mentions

0

No linked articles in our index yet.