{"id":"CVE-2018-17856","aliases":["GHSA-9m72-pw47-292w"],"url":"https://o3.security/vulnerability/CVE-2018-17856","summary":"Joomla RCE Vulnerability","details":"An issue was discovered in Joomla! before 3.8.13. com_joomlaupdate allows the execution of arbitrary code. The default ACL config enabled the ability of Administrator-level users to access com_joomlaupdate and trigger code execution.","published":"2018-10-09T21:29:00.670Z","modified":"2026-07-08T19:44:34.571771Z","cvss":{"score":7.2,"severity":"HIGH","vector":"CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H"},"epss":{"score":0.02312,"percentile":0.8193,"asOf":"2026-08-23"},"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Packagist","name":"joomla/framework","fixedVersion":"3.8.13"}],"fix":null,"references":[{"type":"ADVISORY","url":"http://www.securityfocus.com/bid/105559"},{"type":"ADVISORY","url":"http://www.securitytracker.com/id/1041914"},{"type":"ADVISORY","url":"https://developer.joomla.org/security-centre/752-20181002-core-inadequate-default-access-level-for-com-joomlaupdate.html"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-07-08T19:44:34.571771Z"}}