Joomla! 1.5.6 Released: a critical security fix

This morning the Joomla! dev team released a new Joomla version: 1.5.6.

That’s a released made to correct a security hole that was discovered yesterday: it seems that anyone could get administrator access using the Password Remind functionality, used to reset a password when it’s forgotten.

After a couple of hours the Joomla Team released an official patch on the Joomla.org website.

CompassDesigns.net was hacked because of this problem.

Every Joomla! 1.5 installation is infected by this problem, that now is of public domain. It’s a good idea to upgrade your websites!

Tags: , ,

4 Responses to “Joomla! 1.5.6 Released: a critical security fix”

  1. Copes Flavio Says:

    http://secunia.com/advisories/31457/

  2. Jim Says:

    Too late, I installed Wordpress. All is better now.

  3. Copes Flavio Says:

    Hi Jim, thanks for your comment.

    While I do think that WP is a great piece of software (I’m using it here on my blog) Joomla allows you to do many things that WP simply isn’t developed for.

    So, if you want a blog then WP is the best choice in the world. There’s no fanatism here ;-)

  4. JSST, security-related Joomla squad Says:

    [...] the security hole that lead to the release of Joomla! 1.5.6, the Joomla Core Team decided that it was time to create a group of people devoted to the security [...]

Leave a Reply

Name (obbligatorio)

Mail (will not be published) (obbligatoria)

Website