Vulnerability Database

296,202

Total vulnerabilities in the database

CVE-2015-5397

Cross-site request forgery (CSRF) vulnerability in Joomla! 3.2.0 through 3.3.x and 3.4.x before 3.4.2 allows remote attackers to hijack the authentication of unspecified victims for requests that upload code via unknown vectors.

  • Published: Jul 14, 2015
  • Updated: Apr 13, 2023
  • CVE: CVE-2015-5397
  • Severity: Medium
  • Exploit:

CVSS v2:

  • Severity: Medium
  • Score: 6.8
  • AV:N/AC:M/Au:N/C:P/I:P/A:P

CWEs:

Software From Fixed in
Joomla / joomla 3.4.0-rc1 3.4.0-rc1.x
Joomla / joomla 3.3.3 3.3.3.x
Joomla / joomla 3.2.1 3.2.1.x
Joomla / joomla 3.4.0-beta2 3.4.0-beta2.x
Joomla / joomla 3.4.0-alpha 3.4.0-alpha.x
Joomla / joomla 3.3.5 3.3.5.x
Joomla / joomla 3.4.1-rc2 3.4.1-rc2.x
Joomla / joomla 3.3.4 3.3.4.x
Joomla / joomla 3.3.1 3.3.1.x
Joomla / joomla 3.2.2 3.2.2.x
Joomla / joomla 3.4.1 3.4.1.x
Joomla / joomla 3.4.0-beta3 3.4.0-beta3.x
Joomla / joomla 3.4.0 3.4.0.x
Joomla / joomla 3.4.1-rc1 3.4.1-rc1.x
Joomla / joomla 3.3.0 3.3.0.x
Joomla / joomla 3.2.4 3.2.4.x
Joomla / joomla 3.2.3 3.2.3.x
Joomla / joomla 3.2.0 3.2.0.x
Joomla / joomla 3.3.2 3.3.2.x
Joomla / joomla 3.2.5 3.2.5.x
Joomla / joomla 3.4.0-beta1 3.4.0-beta1.x
Joomla / joomla 3.4.2-rc1 3.4.2-rc1.x