CVE-2016-8870

Severity CVSS v4.0:
Pending analysis
Type:
CWE-20 Input Validation
Publication date:
04/11/2016
Last modified:
12/04/2025

Description

The register method in the UsersModelRegistration class in controllers/user.php in the Users component in Joomla! before 3.6.4, when registration has been disabled, allows remote attackers to create user accounts by leveraging failure to check the Allow User Registration configuration setting.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:joomla:joomla\!:*:*:*:*:*:*:*:* 3.6.3 (including)