Critical account creation flaws patched in popular Joomla CMS
The Joomla developers are warning website administrators to apply an update for the popular content management system that fixes two critical vulnerabilities.
The flaws are serious enough that the Joomla project released a prenotification about the planned update on Friday, urging everyone to be prepared to install it as soon as possible. This suggests that attacks targeting these vulnerabilities are expected to follow shortly.
Joomla 3.6.4, released Tuesday, fixes a high-priority flaw in the account creation component that could be exploited to create accounts on a Joomla-based website even if user registration has been disabled on it.