Webmasters have only hours to deploy patches, Joomla incident shows

Four hours — that’s the time Joomla website owners had to apply a patch recently before attackers started to exploit the flaw it fixed. Those who still haven’t updated their websites are likely to find them compromised.

On Thursday, the developers of Joomla released version 3.4.5 of the popular content management system in order to fix an SQL injection vulnerability that allows attackers to gain administrative privileges by hijacking an active administrator session.

Less than four hours after the update’s release and the publishing of a technical overview by security researchers at Trustwave, attackers were already exploiting the flaw. Web security firm Sucuri said it saw attacks against two of its customers who operate very popular Joomla-based websites.

To read this article in full or to leave a comment, please click here

Read more: Webmasters have only hours to deploy patches, Joomla incident shows

Story added 27. October 2015, content source with full text you can find at link above.