CRITICAL🇵🇱 Wersja polska

CVE-2024-27185

CVSS 9.1v3.1pub. 2024-08-20upd. 2025-06-04

The pagination class includes arbitrary parameters in links, leading to cache poisoning attack vectors.

🤖 AI Analysis
How it works

The class responsible for pagination (page navigation) includes user-supplied parameters in constructed URLs without proper verification. An attacker can craft an HTTP request containing malicious parameters that will be embedded in pagination links and subsequently stored in the server's cache or intermediate caching servers. This mechanism corresponds to CWE-444 classification (inconsistent interpretation of HTTP requests), enabling manipulation of content served to other users from cache.

Impact

An attacker can cause cache poisoning, resulting in serving manipulated content to unsuspecting users and potentially disrupting service availability by invalidating or overwriting correct cache entries.

Mitigation & patch

Apply patches available from the vendor in accordance with the references: https://developer.joomla.org/security-centre/942-20240802-core-cache-poisoning-in-pagination.html

Who is affected

Joomla! — versions indicated in the vendor references (security bulletin 20240802)

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H
  • Joomla Joomla\!

    APP
    Joomla
    3.0.0 – 3.10.17 (excl.)4.0.0 – 4.4.7 (excl.)5.0.0 – 5.1.3 (excl.)
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
References

Related vulnerabilities

CVE-2016-10033CRITICAL9.8⚠ KEVPL ✓same product

PHPMailer — RCE poprzez argument injection w funkcji mailSend

CVE-2026-48902CRITICAL9.8PL ✓same product

Joomla! — degradacja szyfrowania transportu w linkach resetowania hasła i nazwy użytkownika

CVE-2025-25226CRITICAL9.8PL ✓same product

SQL injection w metodzie quoteNameStr pakietu bazy danych Joomla Framework

CVE-2022-23797CRITICAL9.8PL ✓same product

SQL Injection w Joomla! przez niewystarczające filtrowanie wybranych ID

CVE-2022-23795CRITICAL9.8PL ✓same product

Joomla! — obejście uwierzytelnienia umożliwiające przejęcie konta