from Hacker News

Joomla Exploits in the Wild Against CVE-2016-8870 and CVE-2016-8869

by ebarock on 10/28/16, 9:22 PM with 1 comments

  • by faxmachine on 10/28/16, 9:41 PM

    Not sure how, but Joomla, WordPress and other CMS's need to find a better way to improve their security features. It is hard for me to believe that a "high-severity vulnerability that allows remote users to create accounts and increase their privileges on any Joomla" it was just missed all these years.

    A good code review needed to find this.