[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$ftY2PlB1UZiW68knpezsmLqdmLS-c-lXY5NLdo3lvWic":3},{"id":4,"question":5,"answer":6,"answerHtml":7,"slug":8,"keywords":9,"article":10,"status":34,"aiModel":39,"aiConfidence":39,"updatedAt":52,"createdAt":52,"_status":51},1013,"What three conditions must be simultaneously met for an attacker to gain full administrator access via these vulnerabilities?","The attacker requires: (1) Joomla version between 3.4.4 and 3.6.3, (2) the email sending function enabled in the backend (with SMTP configured), and (3) user registration enabled in the backend. Only when all three are true can the attacker create and activate a privileged account. The test record shows that upgrading to 3.6.4 effectively blocks the exploit, and if either email or registration is off, the account never becomes active.","\u003Cp>The attacker requires: (1) Joomla version between 3.4.4 and 3.6.3, (2) the email sending function enabled in the backend (with SMTP configured), and (3) user registration enabled in the backend. Only when all three are true can the attacker create and activate a privileged account. The test record shows that upgrading to 3.6.4 effectively blocks the exploit, and if either email or registration is off, the account never becomes active.\u003C\u002Fp>\u003Cp>\u003Ca href=\"\u002Fnews\u002Fjoomla-3-4-4-3-6-3-account-creation-privilege-escalation-test-record\">Read the related One Day Sec article\u003C\u002Fa>\u003C\u002Fp>","what-three-conditions-must-be-simultaneously-met-for-an-attacker-to-gain-full-ad-1777480662125","Joomla administrator access, attack conditions, email SMTP, user registration enabled, version 3.4.4-3.6.3",{"id":11,"title":12,"slug":13,"description":14,"content":15,"contentHtml":30,"cover":31,"author":32,"views":19,"readingTime":33,"status":34,"publishedAt":35,"seo":36,"tags":41,"qaPairs":42,"meta":48,"updatedAt":49,"createdAt":50,"_status":51},248,"Joomla 3.4.4-3.6.3 Account Creation & Privilege Escalation Test Record","joomla-3-4-4-3-6-3-account-creation-privilege-escalation-test-record","Test record of Joomla 3.4.4-3.6.3 vulnerabilities CVE-2016-8869 and CVE-2016-8870, enabling unauthorized account creation and privilege escalation.",{"root":16},{"type":17,"format":18,"indent":19,"version":20,"children":21,"direction":29},"root","",0,1,[22],{"type":23,"format":18,"indent":19,"version":20,"children":24,"direction":29},"paragraph",[25],{"mode":26,"text":27,"type":28,"style":18,"detail":19,"format":19,"version":20},"normal","\u003Chtml>\u003Chead>\u003C\u002Fhead>\u003Cbody>\u003Ch2>0x00 Introduction\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Vulnerabilities Involved:\u003C\u002Fp>\u003Cul>\u003Cli>CVE-2016-8869\u003C\u002Fli>\u003Cli>CVE-2016-8870\u003C\u002Fli>\u003C\u002Ful>\u003Cp>Using the above vulnerabilities, an attacker can register privileged users\u003C\u002Fp>\u003Cp>\u003Cstrong>POC:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002FXiphosResearch\u002Fexploits\u002Ftree\u002Fmaster\u002FJoomraa\u003C\u002Fp>\u003Cp>https:\u002F\u002Fwww.exploit-db.com\u002Fexploits\u002F40637\u002F?rss\u003C\u002Fp>\u003Cp>\u003Cstrong>Analysis Articles:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>http:\u002F\u002Fpaper.seebug.org\u002F88\u002F\u003C\u002Fp>\u003Cp>http:\u002F\u002Fpaper.seebug.org\u002F86\u002F\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Content in 0x01 and 0x02 is excerpted from the analysis articles\u003C\u002Fp>\u003Cp>http:\u002F\u002Fpaper.seebug.org\u002F88\u002F\u003C\u002Fp>\u003Cp>http:\u002F\u002Fpaper.seebug.org\u002F86\u002F\u003C\u002Fp>\u003Ch2>0x01 CVE-2016-8870\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Ch3>Vulnerability Impact\u003C\u002Fh3>\u003Cp>User creation still possible when website registration is closed\u003C\u002Fp>\u003Ch3>Affected Versions\u003C\u002Fh3>\u003Cp>3.4.4 to 3.6.3\u003C\u002Fp>\u003Ch3>Vulnerability Principle\u003C\u002Fh3>\u003Cp>There are two methods for user registration:\u003C\u002Fp>\u003Cp>UsersControllerRegistration::register() located in components\u002Fcom_users\u002Fcontrollers\u002Fregistration.php\u003C\u002Fp>\u003Cp>UsersControllerUser::register() located in components\u002Fcom_users\u002Fcontrollers\u002Fuser.php\u003C\u002Fp>\u003Cp>Compared to UsersControllerRegistration::register(), the implementation of UsersControllerUser::register() lacks the following lines of code:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>\u002F\u002F If registration is disabled - Redirect to login page.\u003Cbr>if (JComponentHelper::getParams('com_users')-&gt;get('allowUserRegistration') == 0)  \u003Cbr>{\u003Cbr>    $this-&gt;setRedirect(JRoute::_('index.php?option=com_users&amp;view=login', false));\u003Cbr>\u003Cbr>    return false;\u003Cbr>}\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>These lines of code check whether registration is allowed, meaning that if we can use the UsersControllerUser::register() method to register, we can bypass this check.\u003C\u002Fp>\u003Ch3>Patch Analysis\u003C\u002Fh3>\u003Cp>The official fix removed the UsersControllerUser::register() method.\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>The above is quoted from http:\u002F\u002Fpaper.seebug.org\u002F86\u002F\u003C\u002Fp>\u003Ch2>0x02 CVE-2016-8869\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Ch3>Vulnerability Impact\u003C\u002Fh3>\u003Cp>Privileged users can still be created even when site registration is disabled.\u003C\u002Fp>\u003Ch3>Affected Versions\u003C\u002Fh3>\u003Cp>3.4.4 to 3.6.3\u003C\u002Fp>\u003Ch3>Vulnerability Principle\u003C\u002Fh3>\u003Cp>Construct special request packets to assign values to groups representing permissions\u003C\u002Fp>\u003Ch3>Patch Analysis\u003C\u002Fh3>\u003Cp>Official removed the UsersControllerUser::register() method\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>The above is quoted from http:\u002F\u002Fpaper.seebug.org\u002F88\u002F\u003C\u002Fp>\u003Ch2>0x03 Actual Testing\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>\u003Cstrong>Test System:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Win8.1 x86\u003C\u002Fp>\u003Ch3>1. Set up PHP environment\u003C\u002Fh3>\u003Cp>Download and install phpStudy\u003C\u002Fp>\u003Cp>After installation as shown\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770014876558_0_ea540a4fa6.jpeg\">\u003C\u002Fp>\u003Cp>Configure directory as: C:\\WWW\u003C\u002Fp>\u003Ch3>2. Configure Joomla Environment\u003C\u002Fh3>\u003Cp>Download Joomla version 3.6.3 from the following address:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002Fjoomla\u002Fjoomla-cms\u002Freleases\u002Fdownload\u002F3.6.3\u002FJoomla_3.6.3-Stable-Full_Package.tar.gz\u003C\u002Fp>\u003Cp>After extraction, place the files under C:\\WWW\u003C\u002Fp>\u003Cp>Access http:\u002F\u002Flocalhost to enter the installation page\u003C\u002Fp>\u003Cp>As shown in the figure\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770014878344_1_176d9abbc4.png\">\u003C\u002Fp>\u003Cp>Select MySQL as the database type, as shown in the figure\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770014879421_2_c9a3bbfa59.png\">\u003C\u002Fp>\u003Cp>Log in to the database, default password is root\u003C\u002Fp>\u003Cp>As shown in the figure\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770014879823_3_7baad48f55.png\">\u003C\u002Fp>\u003Cp>Wait for the installation to complete\u003C\u002Fp>\u003Ch3>3. Web login, test\u003C\u002Fh3>\u003Cp>Environment configuration successful, as shown in the figure\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770014880932_4_f6cd6e75b8.png\">\u003C\u002Fp>\u003Ch3>4. PoC Testing\u003C\u002Fh3>\u003Cp>\u003Cstrong>PoC Address:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002FXiphosResearch\u002Fexploits\u002Ftree\u002Fmaster\u002FJoomraa\u003C\u002Fp>\u003Cp>\u003Cstrong>Parameters are as follows:\u003C\u002Fstrong>\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>joomraa.py -u hacker -p password -e hacker@example.com http:\u002F\u002F192.168.1.111\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>As shown below, it prompts to log in to the email to view the activation email, so the email parameter needs to be filled with a real email address\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770014882231_5_86a58e6b15.jpeg\">\u003C\u002Fp>\u003Cp>At this point, check the Joomla backend and find that the user has been added successfully, but the status is unactivated, as shown in the figure\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770014882877_6_26df7fd08c.jpeg\">\u003C\u002Fp>\u003Ch3>5. Configure Joomla to enable the function of sending activation emails\u003C\u002Fh3>\u003Cp>Select Global Configuration-Global-Server\u003C\u002Fp>\u003Cp>As shown in the figure\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770014883666_7_4ed15519cd.jpeg\">\u003C\u002Fp>\u003Cp>Set email parameters\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>The email account needs to have SMTP function enabled\u003C\u002Fp>\u003Cp>Select Send Test Mail to verify the email, as shown\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770014884812_8_e89a734aa0.jpeg\">\u003C\u002Fp>\u003Cp>As shown, the verification email is successfully received\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770014885487_9_70de06b87c.png\">\u003C\u002Fp>\u003Ch3>6. Test the POC again\u003C\u002Fh3>\u003Cp>Successfully received the activation email, as shown\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770014886149_10_d6e0ceabec.jpeg\">\u003C\u002Fp>\u003Cp>An error occurs after clicking the link, as shown\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770014886601_11_ea6ccc1f27.jpeg\">\u003C\u002Fp>\u003Cp>Check the Joomla source code, location as follows:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002Fjoomla\u002Fjoomla-cms\u002Fblob\u002Fstaging\u002Fcomponents\u002Fcom_users\u002Fcontrollers\u002Fregistration.php\u003C\u002Fp>\u003Cp>Found the cause of the issue: If user registration or account activation is disabled, throw a 403.\u003C\u002Fp>\u003Cp>As shown below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770014887295_12_5ab6829169.jpeg\">\u003C\u002Fp>\u003Ch3>7. Enable User Registration Function\u003C\u002Fh3>\u003Cp>Select Global Configuration-Users-User Options, click to allow user registration, as shown in the figure\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770014887916_13_ce6c6ef593.jpeg\">\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Since Joomla 3.4, the user registration function is disabled by default\u003C\u002Fp>\u003Ch3>8. Final Test\u003C\u002Fh3>\u003Cp>After enabling the user registration function, click the activation email again to successfully activate the account\u003C\u002Fp>\u003Cp>As shown in the figure\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770014888541_14_961a89c826.jpeg\">\u003C\u002Fp>\u003Cp>The backend shows user activation, as shown in the figure\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770014889482_15_9e1778c1db.jpeg\">\u003C\u002Fp>\u003Ch3>9. Draw the Final Conclusion\u003C\u002Fh3>\u003Cp>Using this vulnerability, privileged users can be created even when user registration is disabled in the backend, but their status remains inactive\u003C\u002Fp>\u003Cp>Only after the email sending function is enabled in the backend can the attacker's email receive the activation email\u003C\u002Fp>\u003Cp>Only when the user registration function is enabled in the website backend can the activation code take effect, allowing users to be activated.\u003C\u002Fp>\u003Cp>Inactive users cannot be used for login.\u003C\u002Fp>\u003Cp>For Joomla versions higher than 3.4, the user registration function is disabled by default.\u003C\u002Fp>\u003Cp>After upgrading Joomla to 3.6.4, the test POC shows a successful attack, but no users are added in the website backend, and no activation emails are sent, indicating successful defense.\u003C\u002Fp>\u003Cp>In summary, for an attacker to gain administrator privileges in the website backend, the following conditions must be met simultaneously:\u003C\u002Fp>\u003Cul>\u003Cli>Joomla version is 3.4.4 to 3.6.3.\u003C\u002Fli>\u003Cli>The email sending function is enabled in the website backend.\u003C\u002Fli>\u003Cli>The user registration function is enabled in the website backend.\u003C\u002Fli>\u003C\u002Ful>\u003Ch2>0x04 Remarks\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Thanks to DM for the assistance.\u003C\u002Fp>\u003Cp>This article is only a test record.\u003C\u002Fp>\u003Cp>Based on the POC, a Python script was developed to check whether a website has the registration function enabled. The address is as follows:\u003C\u002Fp>\u003Cp>An open-source project\u003C\u002Fp>\u003Cp>Can be used to simply determine whether a website supports user registration.\u003C\u002Fp>\u003Cp>\u003Cstrong>This is a reminder to website administrators to upgrade Joomla as soon as possible. If the Joomla version is too low and features such as email sending and user registration are enabled, it is highly vulnerable to attacks.\u003C\u002Fstrong>\u003C\u002Fp>\u003C\u002Fbody>\u003C\u002Fhtml>","text","ltr","\u003Chtml>\u003Chead>\u003C\u002Fhead>\u003Cbody>\u003Ch2>0x00 Introduction\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Vulnerabilities Involved:\u003C\u002Fp>\u003Cul>\u003Cli>CVE-2016-8869\u003C\u002Fli>\u003Cli>CVE-2016-8870\u003C\u002Fli>\u003C\u002Ful>\u003Cp>Using the above vulnerabilities, an attacker can register privileged users\u003C\u002Fp>\u003Cp>\u003Cstrong>POC:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002FXiphosResearch\u002Fexploits\u002Ftree\u002Fmaster\u002FJoomraa\u003C\u002Fp>\u003Cp>https:\u002F\u002Fwww.exploit-db.com\u002Fexploits\u002F40637\u002F?rss\u003C\u002Fp>\u003Cp>\u003Cstrong>Analysis Articles:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>http:\u002F\u002Fpaper.seebug.org\u002F88\u002F\u003C\u002Fp>\u003Cp>http:\u002F\u002Fpaper.seebug.org\u002F86\u002F\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Content in 0x01 and 0x02 is excerpted from the analysis articles\u003C\u002Fp>\u003Cp>http:\u002F\u002Fpaper.seebug.org\u002F88\u002F\u003C\u002Fp>\u003Cp>http:\u002F\u002Fpaper.seebug.org\u002F86\u002F\u003C\u002Fp>\u003Ch2>0x01 CVE-2016-8870\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Ch3>Vulnerability Impact\u003C\u002Fh3>\u003Cp>User creation still possible when website registration is closed\u003C\u002Fp>\u003Ch3>Affected Versions\u003C\u002Fh3>\u003Cp>3.4.4 to 3.6.3\u003C\u002Fp>\u003Ch3>Vulnerability Principle\u003C\u002Fh3>\u003Cp>There are two methods for user registration:\u003C\u002Fp>\u003Cp>UsersControllerRegistration::register() located in components\u002Fcom_users\u002Fcontrollers\u002Fregistration.php\u003C\u002Fp>\u003Cp>UsersControllerUser::register() located in components\u002Fcom_users\u002Fcontrollers\u002Fuser.php\u003C\u002Fp>\u003Cp>Compared to UsersControllerRegistration::register(), the implementation of UsersControllerUser::register() lacks the following lines of code:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>\u002F\u002F If registration is disabled - Redirect to login page.\u003Cbr>if (JComponentHelper::getParams('com_users')-&gt;get('allowUserRegistration') == 0)  \u003Cbr>{\u003Cbr>    $this-&gt;setRedirect(JRoute::_('index.php?option=com_users&amp;view=login', false));\u003Cbr>\u003Cbr>    return false;\u003Cbr>}\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>These lines of code check whether registration is allowed, meaning that if we can use the UsersControllerUser::register() method to register, we can bypass this check.\u003C\u002Fp>\u003Ch3>Patch Analysis\u003C\u002Fh3>\u003Cp>The official fix removed the UsersControllerUser::register() method.\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>The above is quoted from http:\u002F\u002Fpaper.seebug.org\u002F86\u002F\u003C\u002Fp>\u003Ch2>0x02 CVE-2016-8869\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Ch3>Vulnerability Impact\u003C\u002Fh3>\u003Cp>Privileged users can still be created even when site registration is disabled.\u003C\u002Fp>\u003Ch3>Affected Versions\u003C\u002Fh3>\u003Cp>3.4.4 to 3.6.3\u003C\u002Fp>\u003Ch3>Vulnerability Principle\u003C\u002Fh3>\u003Cp>Construct special request packets to assign values to groups representing permissions\u003C\u002Fp>\u003Ch3>Patch Analysis\u003C\u002Fh3>\u003Cp>Official removed the UsersControllerUser::register() method\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>The above is quoted from http:\u002F\u002Fpaper.seebug.org\u002F88\u002F\u003C\u002Fp>\u003Ch2>0x03 Actual Testing\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>\u003Cstrong>Test System:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Win8.1 x86\u003C\u002Fp>\u003Ch3>1. Set up PHP environment\u003C\u002Fh3>\u003Cp>Download and install phpStudy\u003C\u002Fp>\u003Cp>After installation as shown\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770014876558_0_ea540a4fa6-1.jpeg\">\u003C\u002Fp>\u003Cp>Configure directory as: C:\\WWW\u003C\u002Fp>\u003Ch3>2. Configure Joomla Environment\u003C\u002Fh3>\u003Cp>Download Joomla version 3.6.3 from the following address:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002Fjoomla\u002Fjoomla-cms\u002Freleases\u002Fdownload\u002F3.6.3\u002FJoomla_3.6.3-Stable-Full_Package.tar.gz\u003C\u002Fp>\u003Cp>After extraction, place the files under C:\\WWW\u003C\u002Fp>\u003Cp>Access http:\u002F\u002Flocalhost to enter the installation page\u003C\u002Fp>\u003Cp>As shown in the figure\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770014878344_1_176d9abbc4-1.png\">\u003C\u002Fp>\u003Cp>Select MySQL as the database type, as shown in the figure\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770014879421_2_c9a3bbfa59-1.png\">\u003C\u002Fp>\u003Cp>Log in to the database, default password is root\u003C\u002Fp>\u003Cp>As shown in the figure\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770014879823_3_7baad48f55-1.png\">\u003C\u002Fp>\u003Cp>Wait for the installation to complete\u003C\u002Fp>\u003Ch3>3. Web login, test\u003C\u002Fh3>\u003Cp>Environment configuration successful, as shown in the figure\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770014880932_4_f6cd6e75b8-1.png\">\u003C\u002Fp>\u003Ch3>4. PoC Testing\u003C\u002Fh3>\u003Cp>\u003Cstrong>PoC Address:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002FXiphosResearch\u002Fexploits\u002Ftree\u002Fmaster\u002FJoomraa\u003C\u002Fp>\u003Cp>\u003Cstrong>Parameters are as follows:\u003C\u002Fstrong>\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>joomraa.py -u hacker -p password -e hacker@example.com http:\u002F\u002F192.168.1.111\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>As shown below, it prompts to log in to the email to view the activation email, so the email parameter needs to be filled with a real email address\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770014882231_5_86a58e6b15-1.jpeg\">\u003C\u002Fp>\u003Cp>At this point, check the Joomla backend and find that the user has been added successfully, but the status is unactivated, as shown in the figure\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770014882877_6_26df7fd08c-1.jpeg\">\u003C\u002Fp>\u003Ch3>5. Configure Joomla to enable the function of sending activation emails\u003C\u002Fh3>\u003Cp>Select Global Configuration-Global-Server\u003C\u002Fp>\u003Cp>As shown in the figure\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770014883666_7_4ed15519cd-1.jpeg\">\u003C\u002Fp>\u003Cp>Set email parameters\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>The email account needs to have SMTP function enabled\u003C\u002Fp>\u003Cp>Select Send Test Mail to verify the email, as shown\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770014884812_8_e89a734aa0-1.jpeg\">\u003C\u002Fp>\u003Cp>As shown, the verification email is successfully received\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770014885487_9_70de06b87c-1.png\">\u003C\u002Fp>\u003Ch3>6. Test the POC again\u003C\u002Fh3>\u003Cp>Successfully received the activation email, as shown\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770014886149_10_d6e0ceabec-1.jpeg\">\u003C\u002Fp>\u003Cp>An error occurs after clicking the link, as shown\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770014886601_11_ea6ccc1f27-1.jpeg\">\u003C\u002Fp>\u003Cp>Check the Joomla source code, location as follows:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002Fjoomla\u002Fjoomla-cms\u002Fblob\u002Fstaging\u002Fcomponents\u002Fcom_users\u002Fcontrollers\u002Fregistration.php\u003C\u002Fp>\u003Cp>Found the cause of the issue: If user registration or account activation is disabled, throw a 403.\u003C\u002Fp>\u003Cp>As shown below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770014887295_12_5ab6829169-1.jpeg\">\u003C\u002Fp>\u003Ch3>7. Enable User Registration Function\u003C\u002Fh3>\u003Cp>Select Global Configuration-Users-User Options, click to allow user registration, as shown in the figure\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770014887916_13_ce6c6ef593-1.jpeg\">\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Since Joomla 3.4, the user registration function is disabled by default\u003C\u002Fp>\u003Ch3>8. Final Test\u003C\u002Fh3>\u003Cp>After enabling the user registration function, click the activation email again to successfully activate the account\u003C\u002Fp>\u003Cp>As shown in the figure\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770014888541_14_961a89c826-1.jpeg\">\u003C\u002Fp>\u003Cp>The backend shows user activation, as shown in the figure\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770014889482_15_9e1778c1db-1.jpeg\">\u003C\u002Fp>\u003Ch3>9. Draw the Final Conclusion\u003C\u002Fh3>\u003Cp>Using this vulnerability, privileged users can be created even when user registration is disabled in the backend, but their status remains inactive\u003C\u002Fp>\u003Cp>Only after the email sending function is enabled in the backend can the attacker's email receive the activation email\u003C\u002Fp>\u003Cp>Only when the user registration function is enabled in the website backend can the activation code take effect, allowing users to be activated.\u003C\u002Fp>\u003Cp>Inactive users cannot be used for login.\u003C\u002Fp>\u003Cp>For Joomla versions higher than 3.4, the user registration function is disabled by default.\u003C\u002Fp>\u003Cp>After upgrading Joomla to 3.6.4, the test POC shows a successful attack, but no users are added in the website backend, and no activation emails are sent, indicating successful defense.\u003C\u002Fp>\u003Cp>In summary, for an attacker to gain administrator privileges in the website backend, the following conditions must be met simultaneously:\u003C\u002Fp>\u003Cul>\u003Cli>Joomla version is 3.4.4 to 3.6.3.\u003C\u002Fli>\u003Cli>The email sending function is enabled in the website backend.\u003C\u002Fli>\u003Cli>The user registration function is enabled in the website backend.\u003C\u002Fli>\u003C\u002Ful>\u003Ch2>0x04 Remarks\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Thanks to DM for the assistance.\u003C\u002Fp>\u003Cp>This article is only a test record.\u003C\u002Fp>\u003Cp>Based on the POC, a Python script was developed to check whether a website has the registration function enabled. The address is as follows:\u003C\u002Fp>\u003Cp>An open-source project\u003C\u002Fp>\u003Cp>Can be used to simply determine whether a website supports user registration.\u003C\u002Fp>\u003Cp>\u003Cstrong>This is a reminder to website administrators to upgrade Joomla as soon as possible. If the Joomla version is too low and features such as email sending and user registration are enabled, it is highly vulnerable to attacks.\u003C\u002Fstrong>\u003C\u002Fp>\u003C\u002Fbody>\u003C\u002Fhtml>",435,"Onedaysec",4,"published","2026-02-02T07:25:19.985Z",{"title":37,"description":14,"keywords":38,"ogImage":39,"canonicalUrl":39,"noIndex":40},"Joomla 3.4.4-3.6.3 Account Creation & Privilege Escalation Test","Joomla vulnerability, CVE-2016-8869, CVE-2016-8870, privilege escalation, account creation, security testing, Joomla exploit, user registration bypass",null,false,[],{"docs":43,"hasNextPage":40},[44,45,4,46,47],1015,1014,1012,1011,{"title":39,"description":39,"image":39},"2026-07-24T15:37:10.212Z","2026-07-23T16:02:25.495Z","draft","2026-07-23T16:16:07.884Z"]