
More improvements to Attack Surface Custom Policies
Tl;dr We’ve made a few improvements to Attack Surface Custom Policies, such as viewing alerts more easily and deleting custom policies. We’ve also made a …

Detectify Admin
![[Alert] Critical authentication bypass + privilege escalation exploit in Joomla](/_next/image/?url=https%3A%2F%2Fblog-detectify-api.stage.io-ext.se%2Fapp%2Fuploads%2F2022%2F11%2FJoomla-3D-Vertical-logo-light-background-en.png&w=3840&q=75)
A critical authentication bypass and privilege escalation exploit has been discovered by Melvin Lammerts. The exploit affects all Joomla versions from 3.4.4 through 3.6.3. The vulnerability is extremely critical and allows attackers to register an account with admin privileges.
[Solution] Upgrade to Joomla version 3.6.4
Read a more recent write up by Fortinet.
As always, we recommend you to run regular security tests on your website to keep up with all the latest vulnerabilities.
Stay safe!

Tl;dr We’ve made a few improvements to Attack Surface Custom Policies, such as viewing alerts more easily and deleting custom policies. We’ve also made a …

Validate security policies like you mean it Not everything on your attack surface is a vulnerability. Every organization has their own internal security policies that …