KEVIntel
5.3
CVSS
Medium

CVE-2023-23752

PUBLISHED

[20230201] - Core - Improper access check in webservice endpoints

Exploited in the wild Remote Low complexity No user interaction
Vendor
Joomla! Project
Product
Joomla! CMS
Published
Feb 16, 2023
EPSS

Description

An issue was discovered in Joomla! 4.0.0 through 4.2.7. An improper access check allows unauthorized access to webservice endpoints.

joomla cisa nuclei_scanner

CVSS scores

CVSS v3.1 5.3 Medium

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

Exploitation status

Exploited in the wild

Recorded 2024-01-08 00:00:00 UTC · Source

SSVC decision points

Exploitation
active
Automatable
Yes
Technical impact
partial

Known exploited vulnerability sources

Catalogues that list this CVE as a known exploited vulnerability.

Source Added
CISA Jan 08, 2024

Scanner integrations

Potential proof of concepts

These PoCs are unverified and could contain malware. Use at your own risk.

mil4ne/CVE-2023-23752-Joomla-v4.2.8

github · Created 2024-05-05 16:16:03 UTC · 5 stars

0xWhoami35/CVE-2023-23752

github · Created 2024-04-11 13:39:44 UTC · 2 stars

JohnDoeAnonITA/CVE-2023-23752

github · Created 2024-03-12 10:59:10 UTC · 3 stars

CVE-2023-23752 Data Extractor

TindalyTn/CVE-2023-23752

github · Created 2023-12-20 20:20:15 UTC · 0 stars

Mass Scanner for CVE-2023-23752

K3ysTr0K3R/CVE-2023-23752-EXPLOIT

github · Created 2023-12-04 13:05:08 UTC · 10 stars

A PoC exploit for CVE-2023-23752 - Joomla Improper Access Check in Versions 4.0.0 through 4.2.7

Fernando-olv/Joomla-CVE-2023-23752

github · Created 2023-12-01 02:25:04 UTC · 4 stars

This Python implementation serves an educational purpose by demonstrating the exploitation of CVE-2023-23752. The code provides insight into the vulnerability's exploitation.

Youns92/Joomla-v4.2.8---CVE-2023-23752

github · Created 2023-11-28 16:08:16 UTC · 3 stars

CVE-2023-23752

Sweelg/CVE-2023-23752

github · Created 2023-06-16 07:53:22 UTC · 4 stars

Joomla未授权访问漏洞

ThatNotEasy/CVE-2023-23752

github · Created 2023-04-09 13:20:48 UTC · 34 stars

Perform With Mass Exploiter In Joomla 4.2.8.

adhikara13/CVE-2023-23752

github · Created 2023-04-04 21:14:19 UTC · 3 stars

Poc for CVE-2023-23752

0xNahim/CVE-2023-23752

github · Created 2023-03-26 13:58:14 UTC · 5 stars

karthikuj/CVE-2023-23752-Docker

github · Created 2023-03-25 06:18:46 UTC · 4 stars

Joomla Unauthorized Access Vulnerability (CVE-2023-23752) Dockerized

Acceis/exploit-CVE-2023-23752

github · Created 2023-03-24 11:50:16 UTC · 83 stars

Joomla! < 4.2.8 - Unauthenticated information disclosure

Jenderal92/Joomla-CVE-2023-23752

github · Created 2023-03-11 11:20:44 UTC · 0 stars

python 2.7

gibran-abdillah/CVE-2023-23752

github · Created 2023-03-09 07:42:03 UTC · 8 stars

Bulk scanner + get config from CVE-2023-23752

GhostToKnow/CVE-2023-23752

github · Created 2023-03-09 07:32:06 UTC · 2 stars

开源,go多并发批量探测poc,准确率高

adriyansyah-mf/CVE-2023-23752

github · Created 2023-03-07 12:32:17 UTC · 0 stars

keyuan15/CVE-2023-23752

github · Created 2023-03-01 15:28:24 UTC · 12 stars

Joomla 未授权访问漏洞 CVE-2023-23752

z3n70/CVE-2023-23752

github · Created 2023-02-24 01:33:55 UTC · 16 stars

simple program for joomla CVE-2023-23752 scanner for pentesting and educational purpose

ifacker/CVE-2023-23752-Joomla

github · Created 2023-02-23 04:37:31 UTC · 3 stars

CVE-2023-23752 Joomla 未授权访问漏洞 poc

ibaiw/joomla_CVE-2023-23752

github · Created 2023-02-23 01:52:02 UTC · 2 stars

未授权访问漏洞

Vulnmachines/joomla_CVE-2023-23752

github · Created 2023-02-20 10:30:17 UTC · 3 stars

Joomla! 4.0.0 through 4.2.7. An improper access check allows unauthorized access to webservice endpoints.

Saboor-Hakimi/CVE-2023-23752

github · Created 2023-02-18 12:19:24 UTC · 2 stars

CVE-2023-23752 nuclei template

yusinomy/CVE-2023-23752

github · Created 2023-02-18 03:36:54 UTC · 2 stars

Joomla! 未授权访问漏洞

Timeline

  • CVE ID Reserved

  • CVE Published to Public

  • Added to KEVIntel

  • Detected by Nuclei