The pagination class includes arbitrary parameters in links, leading to cache poisoning attack vectors.
The class responsible for pagination (page navigation) includes user-supplied parameters in constructed URLs without proper verification. An attacker can craft an HTTP request containing malicious parameters that will be embedded in pagination links and subsequently stored in the server's cache or intermediate caching servers. This mechanism corresponds to CWE-444 classification (inconsistent interpretation of HTTP requests), enabling manipulation of content served to other users from cache.
An attacker can cause cache poisoning, resulting in serving manipulated content to unsuspecting users and potentially disrupting service availability by invalidating or overwriting correct cache entries.
Apply patches available from the vendor in accordance with the references: https://developer.joomla.org/security-centre/942-20240802-core-cache-poisoning-in-pagination.html
Joomla! — versions indicated in the vendor references (security bulletin 20240802)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:HJoomla Joomla\!
APPJoomla3.0.0 – 3.10.17 (excl.)4.0.0 – 4.4.7 (excl.)5.0.0 – 5.1.3 (excl.)
Related vulnerabilities
PHPMailer — RCE poprzez argument injection w funkcji mailSend
Joomla! — degradacja szyfrowania transportu w linkach resetowania hasła i nazwy użytkownika
SQL injection w metodzie quoteNameStr pakietu bazy danych Joomla Framework
SQL Injection w Joomla! przez niewystarczające filtrowanie wybranych ID
Joomla! — obejście uwierzytelnienia umożliwiające przejęcie konta