Security

Joomla handed the database password to anyone who asked

Joomla handed the database password to anyone who asked

Some flaws require cunning. And some come down to opening one address in a browser. That second category is the most dangerous, because anyone can exploit it. Joomla had exactly such a flaw in 2023.

What happened

Joomla 4 introduced a new API (an interface for applications). There was a bug in its access control (CVE-2023-23752): certain addresses returned the full site configuration without logging in, including the database username and password.

With the database password, an attacker can read or change everything: accounts, content, settings. The flaw was so serious that it made the official list of actively exploited vulnerabilities kept by the US agency CISA. It affected versions 4.0.0-4.2.7; the fix came with 4.2.8.

Why it is so dangerous

Leaking database credentials is not "part of the problem", it is the key to everything. And because the attack came down to visiting a specific address, bots combed the internet for vulnerable sites in bulk.

What to do

  • Make sure your Joomla is updated to at least 4.2.8 (ideally the latest).
  • If you suspect your site was vulnerable, change the database password and review the administrator accounts.
  • Restrict access to the API if you do not use it.

Flaws like this are an argument for someone continuously following Joomla's bulletins. We do it as part of our care service, see what it covers.

Sources: NVD, CVE-2023-23752, CISA KEV.

Related articles

Related services

Free security audit

Do not wait for the site to go down

Send us your website address through the form. We will check it for threats and performance, and you get concrete recommendations plus a free security quote.

Request a free audit →

No obligation · Contact via the form · Reply within 1 business day

Looking for a fresh start? We will build your site from scratch, fast and secure. See the MP WebSolutions offer.