4.3
CVSSv2

CVE-2017-9934

Published: 17/07/2017 Updated: 21/07/2017
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
CVSS v3 Base Score: 6.1 | Impact Score: 2.7 | Exploitability Score: 2.8
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

Missing CSRF token checks and improper input validation in Joomla! CMS 1.7.3 up to and including 3.7.2 lead to an XSS vulnerability.

Vulnerable Product Search on Vulmon Subscribe to Product

joomla joomla\\! 3.7.0

joomla joomla\\! 3.3.4

joomla joomla\\! 3.3.5

joomla joomla\\! 3.4.0

joomla joomla\\! 3.4.8

joomla joomla\\! 3.5.0

joomla joomla\\! 3.6.0

joomla joomla\\! 2.5.1

joomla joomla\\! 2.5.2

joomla joomla\\! 2.5.3

joomla joomla\\! 2.5.4

joomla joomla\\! 2.5.18

joomla joomla\\! 2.5.19

joomla joomla\\! 2.5.20

joomla joomla\\! 2.5.21

joomla joomla\\! 3.1.0

joomla joomla\\! 3.1.1

joomla joomla\\! 3.1.2

joomla joomla\\! 3.1.3

joomla joomla\\! 3.1.4

joomla joomla\\! 3.7.1

joomla joomla\\! 3.6.5

joomla joomla\\! 3.3.0

joomla joomla\\! 3.3.2

joomla joomla\\! 3.4.3

joomla joomla\\! 3.4.5

joomla joomla\\! 3.4.7

joomla joomla\\! 3.5.1

joomla joomla\\! 3.6.1

joomla joomla\\! 3.6.3

joomla joomla\\! 1.7.3

joomla joomla\\! 1.7.5

joomla joomla\\! 2.5.6

joomla joomla\\! 2.5.8

joomla joomla\\! 2.5.15

joomla joomla\\! 2.5.17

joomla joomla\\! 2.5.22

joomla joomla\\! 2.5.24

joomla joomla\\! 3.0.2

joomla joomla\\! 3.0.4

joomla joomla\\! 3.2.0

joomla joomla\\! 3.2.1

joomla joomla\\! 3.2.2

joomla joomla\\! 3.2.3

joomla joomla\\! 3.2.4

joomla joomla\\! 3.4.1

joomla joomla\\! 3.4.2

joomla joomla\\! 3.6.4

joomla joomla\\! 2.5.9

joomla joomla\\! 2.5.10

joomla joomla\\! 2.5.11

joomla joomla\\! 2.5.12

joomla joomla\\! 2.5.13

joomla joomla\\! 2.5.26

joomla joomla\\! 2.5.27

joomla joomla\\! 2.5.28

joomla joomla\\! 3.0.0

joomla joomla\\! 3.7.2

joomla joomla\\! 3.1.6

joomla joomla\\! 3.3.1

joomla joomla\\! 3.3.3

joomla joomla\\! 3.4.4

joomla joomla\\! 3.4.6

joomla joomla\\! 3.6.2

joomla joomla\\! 1.7.4

joomla joomla\\! 2.5.0

joomla joomla\\! 2.5.5

joomla joomla\\! 2.5.7

joomla joomla\\! 2.5.14

joomla joomla\\! 2.5.16

joomla joomla\\! 2.5.23

joomla joomla\\! 2.5.25

joomla joomla\\! 3.0.1

joomla joomla\\! 3.0.3

joomla joomla\\! 3.1.5

Github Repositories

Joomla 1.7.3 - 3.7.2 CSRF exploit PoC

CVE-2017-9934 (I am the reporter of this exploit, under name: Envo) Joomla 173 - 372 CSRF exploit PoC This vulnerability works due to Joomla versions 173 to 372 not sanitizing base64 input #Headers: POST localhost/joomla/administrator/indexphp?option=com_menus&view=item&client_id=0&layout=edit&id=0 HTTP/11 User-Agent: Mozilla/5