What happened
Joomla! contains an improper access control vulnerability that allows unauthorized access to webservice endpoints.
Affected versions
Joomla!: See original advisory Fixed: See vendor advisory.
Why it matters
This source correlation may provide earlier visibility while structured CVE metadata is still being updated.
Detection & mitigation
- Review the original advisory and validate affected versions.
- Apply vendor-provided updates or mitigations when available.
Public PoC references
RepositoryAuthorFirst seenReference
Exploit-DB 51334Joomla! v4.2.8 - Unauthenticated information disclosureAlexandre ZANNI2023-04-08VerifiedPoC-in-GitHub · yusinomy/CVE-2023-23752Joomla! 未授权访问漏洞★ 2yusinomy2023-02-18CandidatePoC-in-GitHub · Saboor-Hakimi/CVE-2023-23752CVE-2023-23752 nuclei template★ 3Saboor-Hakimi2023-02-18CandidatePoC-in-GitHub · Vulnmachines/joomla_CVE-2023-23752Joomla! 4.0.0 through 4.2.7. An improper access check allows unauthorized access to webservice endpoints.★ 3Vulnmachines2023-02-20CandidatePoC-in-GitHub · sw0rd1ight/CVE-2023-23752Poc for CVE-2023-23752 (joomla CMS)★ 0sw0rd1ight2023-02-21CandidatePoC-in-GitHub · wangking1/CVE-2023-23752-pocCVE-2023-23752 poc★ 1wangking12023-02-23CandidatePoC-in-GitHub · ibaiw/joomla_CVE-2023-23752未授权访问漏洞★ 2ibaiw2023-02-23CandidatePoC-in-GitHub · ifacker/CVE-2023-23752-JoomlaCVE-2023-23752 Joomla 未授权访问漏洞 poc★ 3ifacker2023-02-23CandidatePoC-in-GitHub · z3n70/CVE-2023-23752simple program for joomla CVE-2023-23752 scanner for pentesting and educational purpose★ 17z3n702023-02-24CandidatePoC-in-GitHub · keyuan15/CVE-2023-23752Joomla 未授权访问漏洞 CVE-2023-23752★ 12keyuan152023-03-01CandidatePoC-in-GitHub · adriyansyah-mf/CVE-2023-23752★ 0adriyansyah-mf2023-03-07CandidatePoC-in-GitHub · GhostToKnow/CVE-2023-23752开源,go多并发批量探测poc,准确率高★ 2GhostToKnow2023-03-09CandidatePoC-in-GitHub · gibran-abdillah/CVE-2023-23752Bulk scanner + get config from CVE-2023-23752★ 7gibran-abdillah2023-03-09CandidatePoC-in-GitHub · Jenderal92/Joomla-CVE-2023-23752python 2.7★ 0Jenderal922023-03-11CandidatePoC-in-GitHub · Acceis/exploit-CVE-2023-23752Joomla! < 4.2.8 - Unauthenticated information disclosure★ 94Acceis2023-03-24CandidatePoC-in-GitHub · karthikuj/CVE-2023-23752-DockerJoomla Unauthorized Access Vulnerability (CVE-2023-23752) Dockerized★ 4karthikuj2023-03-25CandidatePoC-in-GitHub · 0xNahim/CVE-2023-23752★ 50xNahim2023-03-26CandidatePoC-in-GitHub · adhikara13/CVE-2023-23752Poc for CVE-2023-23752★ 7adhikara132023-04-04CandidatePoC-in-GitHub · AkbarWiraN/Joomla-ScannerCVE-2023-23752★ 1AkbarWiraN2023-04-06CandidatePoC-in-GitHub · Ap0dexMe0/CVE-2023-23752Perform With Mass Exploiter In Joomla 4.2.8.★ 35Ap0dexMe02023-04-09CandidatePoC-in-GitHub · Sweelg/CVE-2023-23752Joomla未授权访问漏洞★ 4Sweelg2023-06-16CandidatePoC-in-GitHub · MrP4nda1337/CVE-2023-23752simple program for joomla scanner CVE-2023-23752 with target list★ 0MrP4nda13372023-07-26CandidatePoC-in-GitHub · yTxZx/CVE-2023-23752★ 0yTxZx2023-10-20CandidatePoC-in-GitHub · AlissonFaoli/CVE-2023-23752Joomla Unauthenticated Information Disclosure (CVE-2023-23752) exploit★ 1AlissonFaoli2023-10-20CandidatePoC-in-GitHub · Pushkarup/CVE-2023-23752Exploit for CVE-2023-23752 (4.0.0 <= Joomla <= 4.2.7).★ 1Pushkarup2023-10-25CandidatePoC-in-GitHub · blacks1ph0n/CVE-2023-23752Joomla Unauthorized Access Vulnerability★ 2blacks1ph0n2023-10-30CandidatePoC-in-GitHub · Youns92/Joomla-v4.2.8---CVE-2023-23752CVE-2023-23752★ 6Youns922023-11-28CandidatePoC-in-GitHub · Ly0kha/Joomla-CVE-2023-23752-Exploit-ScriptJoomla CVE-2023-23752 Exploit Script★ 0Ly0kha2023-11-29CandidatePoC-in-GitHub · r3dston3/CVE-2023-23752★ 1r3dston32023-11-30CandidatePoC-in-GitHub · svaltheim/CVE-2023-23752★ 0svaltheim2023-11-30CandidatePoC-in-GitHub · Fernando-olv/Joomla-CVE-2023-23752This Python implementation serves an educational purpose by demonstrating the exploitation of CVE-2023-23752. The code provides insight into the vulnerability's exploitation.★ 4Fernando-olv2023-12-01CandidatePoC-in-GitHub · K3ysTr0K3R/CVE-2023-23752-EXPLOITA PoC exploit for CVE-2023-23752 - Joomla Improper Access Check in Versions 4.0.0 through 4.2.7★ 19K3ysTr0K3R2023-12-04CandidatePoC-in-GitHub · hadrian3689/CVE-2023-23752_Joomla★ 0hadrian36892023-12-11CandidatePoC-in-GitHub · C1ph3rX13/CVE-2023-23752CVE-2023-23752 Joomla Unauthenticated Information Disclosure★ 0C1ph3rX132023-12-13CandidatePoC-in-GitHub · JeneralMotors/CVE-2023-23752An access control flaw was identified, potentially leading to unauthorized access to critical webservice endpoints within Joomla! CMS versions 4.0.0 through 4.2.7. This vulnerability could be exploited by attackers to gain unauthorized access to sensitive information or perform unauthorized actions.★ 0JeneralMotors2023-12-18CandidatePoC-in-GitHub · gunzf0x/CVE-2023-23752Binaries for "CVE-2023-23752"★ 0gunzf0x2023-12-19CandidatePoC-in-GitHub · shellvik/CVE-2023-23752Joomla Information disclosure exploit code written in C++.★ 0shellvik2023-12-29CandidatePoC-in-GitHub · Rival420/CVE-2023-23752Joomla! < 4.2.8 - Unauthenticated information disclosure exploit★ 0Rival4202024-02-19CandidatePoC-in-GitHub · JohnDoeAnonITA/CVE-2023-23752CVE-2023-23752 Data Extractor★ 1JohnDoeAnonITA2024-03-12CandidatePoC-in-GitHub · 0xWhoami35/CVE-2023-23752★ 20xWhoami352024-04-11CandidatePoC-in-GitHub · mariovata/CVE-2023-23752-PythonJoomla! < 4.2.8 - Unauthenticated information disclosure★ 0mariovata2024-04-15CandidatePoC-in-GitHub · 0xx01/CVE-2023-23752A simple bash script to exploit Joomla! < 4.2.8 - Unauthenticated information disclosure★ 00xx012024-04-28CandidatePoC-in-GitHub · h3x0v3rl0rd/CVE-2023-23752Joomla! v4.2.8 - Unauthenticated information disclosure★ 1h3x0v3rl0rd2024-05-04CandidatePoC-in-GitHub · Aureum01/CVE-2023-23752A bash automation that exploits the vulnerable endpoints for the Joomla! API 4.0 - 4.2.7★ 0Aureum012024-08-11CandidatePoC-in-GitHub · Marwan651/Joomla-CMS-Full-Lifecycle-PentestA comprehensive full-lifecycle penetration testing project on Joomla 4.2.5 exploiting CVE-2023-23752 inside a Dockerized lab environment★ 0Marwan6512026-05-14CandidatePoC-in-GitHub · Sharma01672/traveller-htbTraveller is an Easy Linux machine featuring a Joomla 4.2.7 travel booking website vulnerable to CVE-2023-23752, an unauthenticated REST API information disclosure that leaks database credentials, leading to admin panel access, remote code execution, and root via sudo misconfiguration.★ 0Sharma016722026-06-21CandidatePoC-in-GitHub · rvzsec/joombruteModern Joomla Auth-attack Toolkit J3 / J4 / J5 - CVE-2023-23752 · CVE-2023-23755 · CVE-2025-25227★ 1rvzsec2026-06-21CandidatePoC-in-GitHub · BardLaudian/CVE-2023-23752Python port of the CVE-2023-23752 exploit — Joomla! < 4.2.8 unauthenticated information disclosure (user list + DB credentials leak)★ 0BardLaudian2026-07-17CandidateSource timeline
Discovered through CISA Known Exploited VulnerabilitiesView source ↗
Added to CISA Known Exploited Vulnerabilities catalogView source ↗
Record history
Record created from the first normalized source observation.
Metadata and source references refreshed.