#JUGL meetings are held on the 3rd Tuesday of each month


  • Project: Joomla!
  • SubProject: CMS
  • Impact: Moderate
  • Severity: Low
  • Versions: 1.5.0 through 3.8.12
  • Exploit type: ACL Violation
  • Reported Date: 2017-December-27
  • Fixed Date: 2018-October-02
  • CVE Number: CVE-2018-17855


In case that an attacker gets access to the mail account of an user who can approve admin verifications in the registration process he can activate himself.

Affected Installs

Joomla! CMS versions 1.5.0 through 3.8.12


Upgrade to version 3.8.13


The JSST at the Joomla! Security Centre.

Reported By: Paul Freeman

Read more

Launch a Full version of Joomla! for FREE (including hosting) Find out More