Joomla! before 1.5 RC4 allows remote authenticated administrators to promote arbitrary users to the administrator group, in violation of the intended security model.
Weaknesses in this category are related to the management of permissions, privileges, and other security features that are used to perform access control.
Link | Tags |
---|---|
http://www.securityfocus.com/bid/28111 | vdb entry |
http://secunia.com/advisories/29257 | third party advisory |
http://www.joomla.org/content/view/4335/116/ | |
http://securitytracker.com/id?1019145 | vdb entry |
http://www.mandriva.com/security/advisories?name=MDVSA-2008:060 | vendor advisory |
http://osvdb.org/43277 | vdb entry |