References https://nvd.nist.gov/vuln/detail/cve-2023-23752 https://developer.joomla.org/security-centre/894-20230201-core-improper-access-check-in-webservice-endpoints.html https://www.secrss.com/articles/52091 https://www.h3c.com/cn/d_202305/1844464_30003_0.htm https://blog.nsfocus.net/joomlacve-2023-23752/ https://www.xbmu.edu.cn/xxh/info/1711/2361.htm https://avd.aliyun.com/detail?id=AVD-2023-23752 https://github.com/keyuan15/CVE-2023-23752 https://github.com/K3ysTr0K3R/CVE-2023-23752-EXPLOIT https://www.exploit-db.com/exploits/51334 https://blog.csdn.net/qq_51577576/article/details/129479673
Related VulnerabilitiesPoCCVE-2026-65761: Joomla Easy Store - SQL InjectionPoCCVE-2026-57827: RSFiles! for Joomla - Arbitrary File UploadPoCCVE-2026-48939: Joomla iCagenda < 3.9.10 - Unauthenticated Arbitrary File Upload RCEPoCjoomla-com-fabrik-lfi: Joomla! com_fabrik 3.9.11 - Local File InclusionPoCCVE-2026-48907: Joomla! JCE extension < 2.9.99.5 unauthenticated RCEJoomla JCE /index.php com_jce 文件上传漏洞(CVE-2026-48907)PoCjoomla-fpd: Joomla! - Full Path DisclosureCNVD-2019-34135: Joomla configuration.php RCEPoCCVE-2007-4504: Joomla! RSfiles <=1.0.2 - Local File InclusionPoCCVE-2008-4668: Joomla! Image Browser 0.1.5 rc2 - Local File InclusionPoCCVE-2008-4764: Joomla! <=2.0.0 RC2 - Local File InclusionPoCCVE-2008-6080: Joomla! ionFiles 4.4.2 - Local File InclusionPoCCVE-2008-6172: Joomla! Component RWCards 3.0.11 - Local File Inclusion