Joomla 3.7, one update, one new flaw, the whole database on display
Updates close flaws, but sometimes a new feature brings a new hole. That is what happened with Joomla 3.7 in 2017: a freshly added component opened the way to one of the more dangerous vulnerabilities of that branch.
What happened
Joomla 3.7 introduced the com_fields component (custom fields). It contained the flaw CVE-2017-8917, an SQL injection accessible without logging in. With a single crafted request an attacker could pull data from the database, including session tokens and administrators' login data, and from there take over the panel.
The flaw affected only version 3.7.0 (earlier ones did not have the component). The fix, 3.7.1, came out fast, but exploits appeared almost immediately after disclosure.
What it teaches
Two things. First, update right after the patch is released, because the window between the flaw going public and mass attacks is often hours. Second, even an updated site can be vulnerable if it happened to land on a version with a new, freshly introduced bug. That is why what counts is not a one-off "I did an update", but constant vigilance.
What to do
- Keep Joomla on the latest version of the branch it supports.
- After every major update, check that the site works and that no new accounts have appeared.
- Consider a web application firewall (WAF) that filters out common SQL injection attempts.
Keeping track of versions and bulletins is tedious but crucial work. We will take it off your hands as part of our care service, reach out.
Source: NVD, CVE-2017-8917.