Vulnerability record · CVE-2016-9838 · published 16 December 2016
CVE-2016-9838: Joomla\! improper access control vulnerability
Joomla · Joomla\!
An issue was discovered in components/com_users/models/registration.php in Joomla! before 3.6.5. Incorrect filtering of registration form data stored to the session on a validation error enables a user to gain access to a registered user's account and reset the user's group mappings, username, and password, as demonstrated by submitting a form that targets the `registration.register` task.
Description
An issue was discovered in components/com_users/models/registration.php in Joomla! before 3.6.5. Incorrect filtering of registration form data stored to the session on a validation error enables a user to gain access to a registered user's account and reset the user's group mappings, username, and password, as demonstrated by submitting a form that targets the `registration.register` task.
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| http://www.securityfocus.com/bid/94893 | Third Party AdvisoryVDB Entry |
| https://www.exploit-db.com/exploits/41157/ | |
| https://www.joomla.org/announcements/release-news/5693-joomla-3-6-5-released.html | PatchVendor Advisory |
| http://www.securityfocus.com/bid/94893 | Third Party AdvisoryVDB Entry |
| https://www.exploit-db.com/exploits/41157/ | |
| https://www.joomla.org/announcements/release-news/5693-joomla-3-6-5-released.html | PatchVendor Advisory |
Track CVE-2016-9838 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2016-9838), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.