Knowledgebase
View categorized listing of all common frequently asked questions.
Video Tutorials (jReviews 2.0)
Create a Movie & TV Show review website.
Customize the jReviews themes.
Review user profiles with the Everywhere addon.
Forum
Community forum
Submit a Ticket
Use your client area email to access the ticket system.
Downloads
Guides, modules and more...
CSV Import for Joomla and jReviews
 
Welcome, Guest. Please login or register.
Did you miss your activation email?
December 02, 2008, 07:58:10 PM
21713 Posts in 4960 Topics by 2844 Members
Latest Member: chotchcala
News: Use your client area email when you sign up to the forum so we can identify you as a trial or licensed user. Otherwise we may not answer your questions.
 
jReviews Support Forum  |  Announcements  |  Announcements  |  Urgent! J1.5 users must upgrade to J1.5.6 to fix security vulnerability « previous next »
Pages: [1]
Author Topic: Urgent! J1.5 users must upgrade to J1.5.6 to fix security vulnerability  (Read 866 times)
Alejandro
Global Moderator
Administrator
Hero Member
*****
Offline Offline

Posts: 8613


« on: August 13, 2008, 08:37:04 AM »

From http://developer.joomla.org/security/news/241-20080801-core-password-remind-functionality.html

Quote
A flaw in the reset token validation mechanism allows for non-validating tokens to be forged. This will allow an unauthenticated, unauthorized user to reset the password of the first enabled user (lowest id). Typically, this is an administrator user. Note, that changing the first users username may lessen the impact of this exploit (since the person who changed the password does not know the login associated with the new password). However, the only way to completely rectify the issue is to upgrade to 1.5.6 (or patch the /components/com_user/models/reset.php file).
Logged

Please take the time to vote and to write a review: http://extensions.joomla.org
Reviews Ahoy! - Submit your jReviews site here.
Pages: [1]
« previous next »
    Jump to: