{"id":5384,"date":"2013-08-05T06:13:56","date_gmt":"2013-08-05T12:13:56","guid":{"rendered":"https:\/\/www.siteground.com\/blog\/?p=5384"},"modified":"2025-09-18T14:49:25","modified_gmt":"2025-09-18T14:49:25","slug":"joomla-vulnerability","status":"publish","type":"post","link":"https:\/\/www.siteground.com\/blog\/joomla-vulnerability\/","title":{"rendered":"Serious Joomla Vulnerability found but we&#8217;ve got you Covered!"},"content":{"rendered":"<p style=\"text-align: justify\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-full wp-image-5393\" src=\"https:\/\/newblog.siteground.com\/en\/wp-content\/uploads\/sites\/2\/2014\/08\/security.png\" alt=\"security\" width=\"540\" height=\"188\"><\/p>\n<p style=\"text-align: justify\">It is mid-summer now but security issues take no vacation. Actually they find the most inappropriate time to appear and make our lives more interesting, to say the least. On Thursday, 25 July the Joomla! Project announced the availability of Joomla 3.1.4\/2.5.13 and many users upgraded their websites because the new releases provide tons of useful new features and bug fixes. One will think: job well done, it is time to hit the beach! But\u2026 On Thursday, 01 August, the Joomla! Project surprisingly&nbsp; announced the immediate availability of Joomla! 3.1.5\/2.5.14. Apparently not much time to sip exotic summer cocktails was allowed. The reason for this extremely short period between the two versions was that a&nbsp;<a href=\"https:\/\/developer.joomla.org\/joomlacode-archive\/issue-31626.html\" target=\"_blank\" rel=\"noopener noreferrer\">critical level security issue<\/a>&nbsp;was discovered just after the previous release and it had the potential to affect all Joomla! CMS versions. Yes, that&#8217;s correct&nbsp; &#8211; we are talking about all the Joomla! sites out there. All versions are affected &#8211; 1.5, 1.6, 1.7, 2.5 and 3. Sounds scary, right? Not if you&#8217;re hosted on SiteGround servers!<\/p>\n<p><!--more--><\/p>\n<h3>Vulnerability Explained<\/h3>\n<p style=\"text-align: justify\">The vulnerability allows Joomla websites to be hacked through the Media Manager. To exploit the vulnerability the attacker should find a Joomla site that allows access to the media manager to its registered users. Then s\/he will register an account and use the vulnerability to upload a malicious shell script to this site through the Media Manager. After that the attacker can do pretty much anything \u2013 edit your files, access your database, delete information, etc.<\/p>\n<h3>How did we resolve the issue for all of our clients?<\/h3>\n<h4>Step 1: We applied a server level solution<\/h4>\n<p style=\"text-align: justify\">As soon as the vulnerability was announced our security team started to develop a server level patch. This is our standard practice when there is an issue that can affect a large number of installations. The idea is to create a layer of protection to all Joomla websites hosted by SiteGround regardless of their current version. We analyzed carefully the vulnerability, the exploit and the payload and came up with ingenious solution that blocks the upload of malicious files through the Media Manager on a server level.<\/p>\n<h4>Step 2: Upgrading Joomla 2.5 and 3<\/h4>\n<p style=\"text-align: justify\">Our Joomla! Auto Update system upgraded the 2.5.x\/3.x applications on our servers to the new versions 2.5.14 and 3.1.5. These were released very timely by the Joomla organization and are no longer vulnerable. Once again the Auto Update system we have developed secured our customers\u2019 websites without any effort on their side.<\/p>\n<h4>Step 3: Patching Joomla 1.5<\/h4>\n<p style=\"text-align: justify\">As Joomla 1.5 is no longer officially supported, there was no upgrade available for it. However, the Joomla team has released a security patch that should be applied manually and we went the extra mile and patched all the old Joomla versions hosted on our servers manually ourselves.<\/p>\n<h3>What to do if you&#8217;re not hosted by SiteGround?<\/h3>\n<p style=\"text-align: justify\">The official solution for Joomla! 2.5.x and 3.x sites is to upgrade your application to the latest stable releases &#8211; <a href=\"https:\/\/www.joomla.org\/announcements\/release-news\/5506-joomla-2-5-14-released.html\" target=\"_blank\" rel=\"noopener noreferrer\">2.5.14<\/a> and <a href=\"https:\/\/www.joomla.org\/announcements\/release-news\/5505-joomla-3-1-5-stable-released.html\" target=\"_blank\" rel=\"noopener noreferrer\">3.1.5<\/a>. Joomla! 1.5.x users should download this Joomla patch, extract the .zip file and manually upload the enclosed files into place.<\/p>\n<p style=\"text-align: justify\">All in all, if you&#8217;re a SiteGround customer you can sit back and enjoy your summer vacation, we got you covered! Otherwise, you will have to put down your cocktail and patch your Joomla! site before it is too late. Of course, you can always transfer to us.<\/p>\n\n\n<p>[subscribe_cta]<\/p>\n","protected":false},"excerpt":{"rendered":"It is mid-summer now but security issues take no vacation. Actually they find the most inappropriate time to appear and make our lives more interesting, to say the least. On Thursday, 25 July the Joomla! Project announced the availability of Joomla 3.1.4\/2.5.13 and many users upgraded their websites because the new releases provide tons of&hellip;","protected":false},"author":57,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[2098,2018,12],"tags":[],"class_list":["post-5384","post","type-post","status-publish","format-standard","hentry","category-hosting-insights","category-product-updates","category-security"],"yoast_head":"<!-- This site is optimized with the Yoast SEO Premium plugin v24.2 (Yoast SEO v24.2) - https:\/\/yoast.com\/wordpress\/plugins\/seo\/ -->\n<title>Serious Joomla Vulnerability found but we&#039;ve got you Covered! : SiteGround Blog<\/title>\n<meta name=\"description\" content=\"It is mid-summer now but security issues take no vacation. Actually they find the most inappropriate time to appear and make our lives more interesting,\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/newblog.siteground.com\/en\/joomla-vulnerability\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Serious Joomla Vulnerability found but we&#039;ve got you Covered!\" \/>\n<meta property=\"og:description\" content=\"It is mid-summer now but security issues take no vacation. Actually they find the most inappropriate time to appear and make our lives more interesting,\" \/>\n<meta property=\"og:url\" content=\"https:\/\/newblog.siteground.com\/en\/joomla-vulnerability\/\" \/>\n<meta property=\"og:site_name\" content=\"SiteGround\" \/>\n<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/siteground\" \/>\n<meta property=\"article:published_time\" content=\"2013-08-05T12:13:56+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2025-09-18T14:49:25+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/newblog.siteground.com\/en\/wp-content\/uploads\/sites\/2\/2014\/08\/security.png\" \/>\n\t<meta property=\"og:image:width\" content=\"540\" \/>\n\t<meta property=\"og:image:height\" content=\"188\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/png\" \/>\n<meta name=\"author\" content=\"Daniel Kanchev\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@siteground\" \/>\n<meta name=\"twitter:site\" content=\"@siteground\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Daniel Kanchev\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"3 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\/\/newblog.siteground.com\/en\/joomla-vulnerability\/#article\",\"isPartOf\":{\"@id\":\"https:\/\/newblog.siteground.com\/en\/joomla-vulnerability\/\"},\"author\":{\"name\":\"Daniel Kanchev\",\"@id\":\"https:\/\/newblog.siteground.com\/en\/#\/schema\/person\/380162a677d6c37329e9a12baa334572\"},\"headline\":\"Serious Joomla Vulnerability found but we&#8217;ve got you Covered!\",\"datePublished\":\"2013-08-05T12:13:56+00:00\",\"dateModified\":\"2025-09-18T14:49:25+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\/\/newblog.siteground.com\/en\/joomla-vulnerability\/\"},\"wordCount\":564,\"commentCount\":10,\"publisher\":{\"@id\":\"https:\/\/newblog.siteground.com\/en\/#organization\"},\"image\":{\"@id\":\"https:\/\/newblog.siteground.com\/en\/joomla-vulnerability\/#primaryimage\"},\"thumbnailUrl\":\"https:\/\/newblog.siteground.com\/en\/wp-content\/uploads\/sites\/2\/2014\/08\/security.png\",\"articleSection\":[\"Hosting Insights\",\"Product Updates\",\"Security\"],\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\/\/newblog.siteground.com\/en\/joomla-vulnerability\/#respond\"]}]},{\"@type\":\"WebPage\",\"@id\":\"https:\/\/newblog.siteground.com\/en\/joomla-vulnerability\/\",\"url\":\"https:\/\/newblog.siteground.com\/en\/joomla-vulnerability\/\",\"name\":\"Serious Joomla Vulnerability found but we've got you Covered! : SiteGround Blog\",\"isPartOf\":{\"@id\":\"https:\/\/newblog.siteground.com\/en\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\/\/newblog.siteground.com\/en\/joomla-vulnerability\/#primaryimage\"},\"image\":{\"@id\":\"https:\/\/newblog.siteground.com\/en\/joomla-vulnerability\/#primaryimage\"},\"thumbnailUrl\":\"https:\/\/newblog.siteground.com\/en\/wp-content\/uploads\/sites\/2\/2014\/08\/security.png\",\"datePublished\":\"2013-08-05T12:13:56+00:00\",\"dateModified\":\"2025-09-18T14:49:25+00:00\",\"description\":\"It is mid-summer now but security issues take no vacation. Actually they find the most inappropriate time to appear and make our lives more interesting,\",\"breadcrumb\":{\"@id\":\"https:\/\/newblog.siteground.com\/en\/joomla-vulnerability\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/newblog.siteground.com\/en\/joomla-vulnerability\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/newblog.siteground.com\/en\/joomla-vulnerability\/#primaryimage\",\"url\":\"https:\/\/newblog.siteground.com\/en\/wp-content\/uploads\/sites\/2\/2014\/08\/security.png\",\"contentUrl\":\"https:\/\/newblog.siteground.com\/en\/wp-content\/uploads\/sites\/2\/2014\/08\/security.png\",\"width\":540,\"height\":188},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\/\/newblog.siteground.com\/en\/joomla-vulnerability\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\/\/newblog.siteground.com\/en\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Serious Joomla Vulnerability found but we&#8217;ve got you Covered!\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/newblog.siteground.com\/en\/#website\",\"url\":\"https:\/\/newblog.siteground.com\/en\/\",\"name\":\"SiteGround Blog\",\"description\":\"\",\"publisher\":{\"@id\":\"https:\/\/newblog.siteground.com\/en\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\/\/newblog.siteground.com\/en\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\/\/newblog.siteground.com\/en\/#organization\",\"name\":\"SiteGround Blog\",\"url\":\"https:\/\/newblog.siteground.com\/en\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/newblog.siteground.com\/en\/#\/schema\/logo\/image\/\",\"url\":\"https:\/\/newblog.siteground.com\/en\/wp-content\/uploads\/sites\/2\/2025\/01\/Siteground-Logo-on-white.jpg\",\"contentUrl\":\"https:\/\/newblog.siteground.com\/en\/wp-content\/uploads\/sites\/2\/2025\/01\/Siteground-Logo-on-white.jpg\",\"width\":1200,\"height\":400,\"caption\":\"SiteGround Blog\"},\"image\":{\"@id\":\"https:\/\/newblog.siteground.com\/en\/#\/schema\/logo\/image\/\"},\"sameAs\":[\"https:\/\/www.facebook.com\/siteground\",\"https:\/\/x.com\/siteground\",\"https:\/\/www.instagram.com\/siteground\/\",\"https:\/\/www.youtube.com\/@siteground\"]},{\"@type\":\"Person\",\"@id\":\"https:\/\/newblog.siteground.com\/en\/#\/schema\/person\/380162a677d6c37329e9a12baa334572\",\"name\":\"Daniel Kanchev\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/newblog.siteground.com\/en\/#\/schema\/person\/image\/\",\"url\":\"https:\/\/secure.gravatar.com\/avatar\/f0baefb86ae4d35a2e71cb0966e1847f?s=96&d=mm&r=g\",\"contentUrl\":\"https:\/\/secure.gravatar.com\/avatar\/f0baefb86ae4d35a2e71cb0966e1847f?s=96&d=mm&r=g\",\"caption\":\"Daniel Kanchev\"},\"sameAs\":[\"https:\/\/www.linkedin.com\/in\/daniel-kanchev-29716455\/\"],\"url\":\"https:\/\/newblog.siteground.com\/en\/author\/daniel\/\"}]}<\/script>\n<!-- \/ Yoast SEO Premium plugin. -->","yoast_head_json":{"title":"Serious Joomla Vulnerability found but we've got you Covered! : SiteGround Blog","description":"It is mid-summer now but security issues take no vacation. Actually they find the most inappropriate time to appear and make our lives more interesting,","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/newblog.siteground.com\/en\/joomla-vulnerability\/","og_locale":"en_US","og_type":"article","og_title":"Serious Joomla Vulnerability found but we've got you Covered!","og_description":"It is mid-summer now but security issues take no vacation. Actually they find the most inappropriate time to appear and make our lives more interesting,","og_url":"https:\/\/newblog.siteground.com\/en\/joomla-vulnerability\/","og_site_name":"SiteGround","article_publisher":"https:\/\/www.facebook.com\/siteground","article_published_time":"2013-08-05T12:13:56+00:00","article_modified_time":"2025-09-18T14:49:25+00:00","og_image":[{"width":540,"height":188,"url":"https:\/\/newblog.siteground.com\/en\/wp-content\/uploads\/sites\/2\/2014\/08\/security.png","type":"image\/png"}],"author":"Daniel Kanchev","twitter_card":"summary_large_image","twitter_creator":"@siteground","twitter_site":"@siteground","twitter_misc":{"Written by":"Daniel Kanchev","Est. reading time":"3 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/newblog.siteground.com\/en\/joomla-vulnerability\/#article","isPartOf":{"@id":"https:\/\/newblog.siteground.com\/en\/joomla-vulnerability\/"},"author":{"name":"Daniel Kanchev","@id":"https:\/\/newblog.siteground.com\/en\/#\/schema\/person\/380162a677d6c37329e9a12baa334572"},"headline":"Serious Joomla Vulnerability found but we&#8217;ve got you Covered!","datePublished":"2013-08-05T12:13:56+00:00","dateModified":"2025-09-18T14:49:25+00:00","mainEntityOfPage":{"@id":"https:\/\/newblog.siteground.com\/en\/joomla-vulnerability\/"},"wordCount":564,"commentCount":10,"publisher":{"@id":"https:\/\/newblog.siteground.com\/en\/#organization"},"image":{"@id":"https:\/\/newblog.siteground.com\/en\/joomla-vulnerability\/#primaryimage"},"thumbnailUrl":"https:\/\/newblog.siteground.com\/en\/wp-content\/uploads\/sites\/2\/2014\/08\/security.png","articleSection":["Hosting Insights","Product Updates","Security"],"inLanguage":"en-US","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/newblog.siteground.com\/en\/joomla-vulnerability\/#respond"]}]},{"@type":"WebPage","@id":"https:\/\/newblog.siteground.com\/en\/joomla-vulnerability\/","url":"https:\/\/newblog.siteground.com\/en\/joomla-vulnerability\/","name":"Serious Joomla Vulnerability found but we've got you Covered! : SiteGround Blog","isPartOf":{"@id":"https:\/\/newblog.siteground.com\/en\/#website"},"primaryImageOfPage":{"@id":"https:\/\/newblog.siteground.com\/en\/joomla-vulnerability\/#primaryimage"},"image":{"@id":"https:\/\/newblog.siteground.com\/en\/joomla-vulnerability\/#primaryimage"},"thumbnailUrl":"https:\/\/newblog.siteground.com\/en\/wp-content\/uploads\/sites\/2\/2014\/08\/security.png","datePublished":"2013-08-05T12:13:56+00:00","dateModified":"2025-09-18T14:49:25+00:00","description":"It is mid-summer now but security issues take no vacation. Actually they find the most inappropriate time to appear and make our lives more interesting,","breadcrumb":{"@id":"https:\/\/newblog.siteground.com\/en\/joomla-vulnerability\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/newblog.siteground.com\/en\/joomla-vulnerability\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/newblog.siteground.com\/en\/joomla-vulnerability\/#primaryimage","url":"https:\/\/newblog.siteground.com\/en\/wp-content\/uploads\/sites\/2\/2014\/08\/security.png","contentUrl":"https:\/\/newblog.siteground.com\/en\/wp-content\/uploads\/sites\/2\/2014\/08\/security.png","width":540,"height":188},{"@type":"BreadcrumbList","@id":"https:\/\/newblog.siteground.com\/en\/joomla-vulnerability\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/newblog.siteground.com\/en\/"},{"@type":"ListItem","position":2,"name":"Serious Joomla Vulnerability found but we&#8217;ve got you Covered!"}]},{"@type":"WebSite","@id":"https:\/\/newblog.siteground.com\/en\/#website","url":"https:\/\/newblog.siteground.com\/en\/","name":"SiteGround Blog","description":"","publisher":{"@id":"https:\/\/newblog.siteground.com\/en\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/newblog.siteground.com\/en\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/newblog.siteground.com\/en\/#organization","name":"SiteGround Blog","url":"https:\/\/newblog.siteground.com\/en\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/newblog.siteground.com\/en\/#\/schema\/logo\/image\/","url":"https:\/\/newblog.siteground.com\/en\/wp-content\/uploads\/sites\/2\/2025\/01\/Siteground-Logo-on-white.jpg","contentUrl":"https:\/\/newblog.siteground.com\/en\/wp-content\/uploads\/sites\/2\/2025\/01\/Siteground-Logo-on-white.jpg","width":1200,"height":400,"caption":"SiteGround Blog"},"image":{"@id":"https:\/\/newblog.siteground.com\/en\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/www.facebook.com\/siteground","https:\/\/x.com\/siteground","https:\/\/www.instagram.com\/siteground\/","https:\/\/www.youtube.com\/@siteground"]},{"@type":"Person","@id":"https:\/\/newblog.siteground.com\/en\/#\/schema\/person\/380162a677d6c37329e9a12baa334572","name":"Daniel Kanchev","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/newblog.siteground.com\/en\/#\/schema\/person\/image\/","url":"https:\/\/secure.gravatar.com\/avatar\/f0baefb86ae4d35a2e71cb0966e1847f?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/f0baefb86ae4d35a2e71cb0966e1847f?s=96&d=mm&r=g","caption":"Daniel Kanchev"},"sameAs":["https:\/\/www.linkedin.com\/in\/daniel-kanchev-29716455\/"],"url":"https:\/\/newblog.siteground.com\/en\/author\/daniel\/"}]}},"_links":{"self":[{"href":"https:\/\/newblog.siteground.com\/en\/wp-json\/wp\/v2\/posts\/5384","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/newblog.siteground.com\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/newblog.siteground.com\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/newblog.siteground.com\/en\/wp-json\/wp\/v2\/users\/57"}],"replies":[{"embeddable":true,"href":"https:\/\/newblog.siteground.com\/en\/wp-json\/wp\/v2\/comments?post=5384"}],"version-history":[{"count":3,"href":"https:\/\/newblog.siteground.com\/en\/wp-json\/wp\/v2\/posts\/5384\/revisions"}],"predecessor-version":[{"id":18055,"href":"https:\/\/newblog.siteground.com\/en\/wp-json\/wp\/v2\/posts\/5384\/revisions\/18055"}],"wp:attachment":[{"href":"https:\/\/newblog.siteground.com\/en\/wp-json\/wp\/v2\/media?parent=5384"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/newblog.siteground.com\/en\/wp-json\/wp\/v2\/categories?post=5384"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/newblog.siteground.com\/en\/wp-json\/wp\/v2\/tags?post=5384"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}