Security

Joomla 3.7, one update, one new flaw, the whole database on display

Joomla 3.7, one update, one new flaw, the whole database on display

Updates close flaws, but sometimes a new feature brings a new hole. That is what happened with Joomla 3.7 in 2017: a freshly added component opened the way to one of the more dangerous vulnerabilities of that branch.

What happened

Joomla 3.7 introduced the com_fields component (custom fields). It contained the flaw CVE-2017-8917, an SQL injection accessible without logging in. With a single crafted request an attacker could pull data from the database, including session tokens and administrators' login data, and from there take over the panel.

The flaw affected only version 3.7.0 (earlier ones did not have the component). The fix, 3.7.1, came out fast, but exploits appeared almost immediately after disclosure.

What it teaches

Two things. First, update right after the patch is released, because the window between the flaw going public and mass attacks is often hours. Second, even an updated site can be vulnerable if it happened to land on a version with a new, freshly introduced bug. That is why what counts is not a one-off "I did an update", but constant vigilance.

What to do

  • Keep Joomla on the latest version of the branch it supports.
  • After every major update, check that the site works and that no new accounts have appeared.
  • Consider a web application firewall (WAF) that filters out common SQL injection attempts.

Keeping track of versions and bulletins is tedious but crucial work. We will take it off your hands as part of our care service, reach out.

Source: NVD, CVE-2017-8917.

Related articles

Related services

Free security audit

Do not wait for the site to go down

Send us your website address through the form. We will check it for threats and performance, and you get concrete recommendations plus a free security quote.

Request a free audit →

No obligation · Contact via the form · Reply within 1 business day

Looking for a fresh start? We will build your site from scratch, fast and secure. See the MP WebSolutions offer.