CVE-2023-40626 Topic is solved

Discussion regarding Joomla! 3.x security issues.

Moderators: mandville, General Support Moderators

Forum rules
Forum Rules
Absolute Beginner's Guide to Joomla! <-- please read before posting, this means YOU.
Forum Post Assistant / FPA - If you are serious about wanting help, you will use this tool to help you post.
Windows Defender SmartScreen Issues <-- please read this if using Windows 10.
Post Reply
User avatar
Webdongle
Joomla! Master
Joomla! Master
Posts: 44096
Joined: Sat Apr 05, 2008 9:58 pm

CVE-2023-40626

Post by Webdongle » Wed Nov 29, 2023 6:32 pm

https://developer.joomla.org/security-c ... ables.html Doesn't mention Joomla! 3.10.12 as being affected. But recommends updating to 3.10.14-elts.
Affected Installs

Joomla! CMS versions 1.6.0-4.4.0, 5.0.0
Solution

Upgrade to version 3.10.14-elts, 4.4.1 or 5.0.1
Does this mean
a. Joomla! 3.10.12 is affected but was just a typo not including it in the Affected Installs
or
b Joomla! 3.10.12 is not affected?
http://www.weblinksonline.co.uk/
https://www.weblinksonline.co.uk/updating-joomla.html
"When I'm right no one remembers but when I'm wrong no one forgets".

User avatar
pe7er
Joomla! Master
Joomla! Master
Posts: 24986
Joined: Thu Aug 18, 2005 8:55 pm
Location: Nijmegen, Netherlands
Contact:

Re: CVE-2023-40626

Post by pe7er » Wed Nov 29, 2023 8:30 pm

Webdongle wrote:
Wed Nov 29, 2023 6:32 pm
https://developer.joomla.org/security-c ... ables.html Doesn't mention Joomla! 3.10.12 as being affected.
Actually, that CVE states "Versions: 1.6.0-4.4.0, 5.0.0"
which I read as that all versions from 1.6.0 to 4.4.0, and 5.0.0 are affected.
So I suppose that Joomla 3.10.12 is affected as well...
Kind Regards,
Peter Martin, Global Moderator
Company website: https://db8.nl/en/ - Joomla specialist, Nijmegen, Netherlands
The best website: https://the-best-website.com

User avatar
brian
Joomla! Master
Joomla! Master
Posts: 12787
Joined: Fri Aug 12, 2005 7:19 am
Location: Leeds, UK
Contact:

Re: CVE-2023-40626

Post by brian » Wed Nov 29, 2023 8:40 pm

pe7er is correct - all versions
"Exploited yesterday... Hacked tomorrow"
Blog http://brian.teeman.net/
Joomla Hidden Secrets http://hiddenjoomlasecrets.com/

User avatar
Webdongle
Joomla! Master
Joomla! Master
Posts: 44096
Joined: Sat Apr 05, 2008 9:58 pm

Re: CVE-2023-40626

Post by Webdongle » Wed Nov 29, 2023 9:49 pm

Ah. Cleaned my glasses I see it's a hyphen. Yeah threw me a little the hyphen in the 'Affected Installs' section but the word 'to' in the 'Solution' section. I need sleep been on the laptop 10 hours solid. Thanks for clarifying.
http://www.weblinksonline.co.uk/
https://www.weblinksonline.co.uk/updating-joomla.html
"When I'm right no one remembers but when I'm wrong no one forgets".

User avatar
Webdongle
Joomla! Master
Joomla! Master
Posts: 44096
Joined: Sat Apr 05, 2008 9:58 pm

Re: CVE-2023-40626

Post by Webdongle » Thu Nov 30, 2023 9:38 pm

http://www.weblinksonline.co.uk/
https://www.weblinksonline.co.uk/updating-joomla.html
"When I'm right no one remembers but when I'm wrong no one forgets".

tlweb
Joomla! Apprentice
Joomla! Apprentice
Posts: 13
Joined: Thu Jun 30, 2016 9:08 pm

Re: CVE-2023-40626

Post by tlweb » Sat Dec 02, 2023 12:15 am

Thanks for sharing my little plugin that patches this vulnerability :)

gljoo
Joomla! Apprentice
Joomla! Apprentice
Posts: 45
Joined: Tue Sep 08, 2015 9:12 am

Re: CVE-2023-40626

Post by gljoo » Tue Jan 09, 2024 10:53 am

To apply this patch, can I simply replace the LanguageHelper.php file found in /JoomlaInstallDir/libraries/src/Language/ with the one that can be downloaded from GitHub ?

User avatar
Webdongle
Joomla! Master
Joomla! Master
Posts: 44096
Joined: Sat Apr 05, 2008 9:58 pm

Re: CVE-2023-40626

Post by Webdongle » Tue Jan 09, 2024 11:44 am

Tap the 'Code' button
Download the zip and install Joomla admin Extensions >>> Install
http://www.weblinksonline.co.uk/
https://www.weblinksonline.co.uk/updating-joomla.html
"When I'm right no one remembers but when I'm wrong no one forgets".

gljoo
Joomla! Apprentice
Joomla! Apprentice
Posts: 45
Joined: Tue Sep 08, 2015 9:12 am

Re: CVE-2023-40626

Post by gljoo » Tue Jan 09, 2024 12:19 pm

Hi @Webdongle, thanks for the clarification.

By manually replacing the LanguageHelper.php file, can I avoid installing the extension ?

It seems to me that the script.php file just replaces that file without making any other changes ...

User avatar
Webdongle
Joomla! Master
Joomla! Master
Posts: 44096
Joined: Sat Apr 05, 2008 9:58 pm

Re: CVE-2023-40626

Post by Webdongle » Tue Jan 09, 2024 2:55 pm

Don't know I didn't write the code. I just did it the usual way for installing extensions.
http://www.weblinksonline.co.uk/
https://www.weblinksonline.co.uk/updating-joomla.html
"When I'm right no one remembers but when I'm wrong no one forgets".

gljoo
Joomla! Apprentice
Joomla! Apprentice
Posts: 45
Joined: Tue Sep 08, 2015 9:12 am

Re: CVE-2023-40626

Post by gljoo » Wed Jan 10, 2024 11:02 am

I did not install the plugin, but simply replaced the LanguageHelper.php file with the one that fixes the vulnerability and everything seems to be working properly.


Post Reply

Return to “Security in Joomla! 3.x”