Joomla! 2.5.4 closes more security holes
Two weeks after its last security update, the Joomla! project has published another update to the 2.5.x branch of its open source content management system (CMS) which addresses two vulnerabilities. Version 2.5.4 of Joomla! closes an information disclosure hole that allowed unauthorised access to administrative information and fixes a problem that could have been exploited by an attacker to conduct cross-site scripting (XSS) attacks. Versions 2.5.0 to 2.5.3 are affected.
The update to Joomla! 2.5 also adds three new features, including an option to show the full CMS version number in the generator tag, and fixes more than 150 bugs. All users are advised to upgrade.
A full list of changes and fixes can be found in the release announcement and in the security advisories. Version 2.5.4 of Joomla! is available to download from the project's site and is licensed under the GPL.
See also:
- [20120307] - Core - Information Disclosure, a Joomla! security advisory.
- [20120308] - Core - XSS Vulnerability, a Joomla! security advisory.
(crve)