Joomla handed the database password to anyone who asked
Some flaws require cunning. And some come down to opening one address in a browser. That second category is the most dangerous, because anyone can exploit it. Joomla had exactly such a flaw in 2023.
What happened
Joomla 4 introduced a new API (an interface for applications). There was a bug in its access control (CVE-2023-23752): certain addresses returned the full site configuration without logging in, including the database username and password.
With the database password, an attacker can read or change everything: accounts, content, settings. The flaw was so serious that it made the official list of actively exploited vulnerabilities kept by the US agency CISA. It affected versions 4.0.0-4.2.7; the fix came with 4.2.8.
Why it is so dangerous
Leaking database credentials is not "part of the problem", it is the key to everything. And because the attack came down to visiting a specific address, bots combed the internet for vulnerable sites in bulk.
What to do
- Make sure your Joomla is updated to at least 4.2.8 (ideally the latest).
- If you suspect your site was vulnerable, change the database password and review the administrator accounts.
- Restrict access to the API if you do not use it.
Flaws like this are an argument for someone continuously following Joomla's bulletins. We do it as part of our care service, see what it covers.
Sources: NVD, CVE-2023-23752, CISA KEV.