CVE-2016-8870

Scores

EPSS

0.915high91.5%
0%20%40%60%80%100%

Percentile: 91.5%

CVSS

8.1high3.x
0246810

CVSS Score: 8.1/10

All CVSS Scores

CVSS 3.x
8.1

Vector: CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

CVSS 2.0
6.8

Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Description

The register method in the UsersModelRegistration class in controllers/user.php in the Users component in Joomla! before 3.6.4, when registration has been disabled, allows remote attackers to create user accounts by leveraging failure to check the Allow User Registration configuration setting.

Scaner-VS 7 — a modern vulnerability management solution

Uses this database for vulnerability detection. High-speed search, cross-platform, advanced configuration audit, and flexible filtering. Suitable for organizations of any size.
Learn more about Scaner-VS 7

Sources

nvd

CWEs

CWE-20

Exploits

Exploit ID: 40637

Source: exploitdb

URL: https://www.exploit-db.com/exploits/40637

Exploit ID: CVE-2016-8870

Source: github-poc

URL: https://github.com/cved-sources/cve-2016-8870

Vulnerable Software (1)

Type: Configuration

Vendor: *

Product: joomla!

Operating System: * * *

Trait:
{  "cpe_match": [    {      "cpe23uri": "cpe:2.3:a:joomla:joomla\\!:*:*:*:*:*:*:*:*",      "versionEndIncluding": "3.6.3",      "vulnerable": true    }  ],  "operator": "OR"}

Source: nvd

End of list