{"data":{"id":"CVE-2018-17855","cve_id":"CVE-2018-17855","title":"An issue was discovered in Joomla!","summary":"An issue was discovered in Joomla!","severity":"HIGH","cvss":{"score":8.8,"version":"3.0","vector":"CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","source":"nvd"},"published_at":"2018-10-09T21:29:00.543000Z","modified_at":"2026-06-17T01:46:24.310000Z","withdrawn_at":null,"is_joomla":true,"is_joomla_core":true,"relevance":"certain","product":"Joomla CMS","extension":{"type":null,"name":null},"sources":["nvd"],"source_count":1,"url":"https://cve.oyer.fr/cve/CVE-2018-17855","description":"An issue was discovered in Joomla! before 3.8.13. If an attacker gets access to the mail account of an user who can approve admin verifications in the registration process, he can activate himself.","cwe":["CWE-269"],"affected":[{"package":null,"product":"joomla!","vendor":"joomla","ecosystem":null,"cpe":"cpe:2.3:a:joomla:joomla\\!:*:*:*:*:*:*:*:*","version_start":"1.5.0","version_end":"3.8.13","version_end_inclusive":false,"fixed_version":"3.8.13","type":"core","source":"nvd"}],"references":[{"url":"http://www.securityfocus.com/bid/105559","title":"Third Party Advisory, VDB Entry","source":"nvd"},{"url":"http://www.securitytracker.com/id/1041914","title":"Third Party Advisory, VDB Entry","source":"nvd"},{"url":"https://developer.joomla.org/security-centre/754-20181004-core-acl-violation-in-com-users-for-the-admin-verification","title":"Vendor Advisory","source":"nvd"}],"source_records":[{"source":"nvd","external_id":"CVE-2018-17855","url":"https://nvd.nist.gov/vuln/detail/CVE-2018-17855","severity":"HIGH","cvss_score":8.8,"cvss_vector":"CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","cvss_version":"3.0","first_seen_at":"2026-09-26T09:34:16.878210Z","last_seen_at":"2026-09-26T09:34:16.878210Z"}],"history":[{"at":"2026-09-26T09:34:16.878210Z","event":"created","source":"nvd","detail":"Détectée via nvd"}]}}
