• Skip to primary navigation
  • Skip to content
  • Skip to primary sidebar
  • Skip to footer

Sucuri Blog

Website Security News

  • Products
    • Website Security Platform
    • Website Firewall (WAF)
    • Enterprise Website Security
    • Multisite Solutions
  • Features
    • Detection
    • Protection
    • Performance
    • Response
    • Backups
  • Partners
    • Agency Solutions
    • Partners
    • Referral Program
    • Ecommerce
  • Resources
    • Guides
    • Webinars
    • Infographics
    • SiteCheck
    • Reports
    • Email Courses
  • Immediate Help
  • Login

Joomla 2.5.8 and 3.0.2 Released (Security Updates)

November 8, 2012David Dede

0
SHARES
FacebookTwitterSubscribe

Joomla 2.5.8 and 3.0.2 were just released today fixing a medium severity security bug related to a clickjacking/XSS vulnerability. You can find more details on their release notes:

  • Joomla 2.5.8 released
  • Joomla 3.0.2 released

If you are not familiar with ClickJacking, Wikipedia explains it well:

Clickjacking is a malicious technique of tricking a Web user into clicking on something different to what the user perceives they are clicking on, thus potentially revealing confidential information or taking control of their computer while clicking on seemingly innocuous web pages. It is a browser security issue that is a vulnerability across a variety of browsers and platforms. A clickjack takes the form of embedded code or a script that can execute without the user’s knowledge, such as clicking on a button that appears to perform another function.

And remember, the leading cause for website compromises is outdated software! So as a website owner, you have to do your part to minimize risk and keep your site (and your users) safe. Update now!

Sucuri SiteCheck was also updated to alert users not running version 2.5.8/3.0.2 on their Joomla sites.

0
SHARES
FacebookTwitterSubscribe

Categories: Joomla Security, Vulnerability Disclosure

About David Dede

David is a Security Researcher at Sucuri. He spends most of his time dissecting vulnerabilities and security issues. You won't find him on Twitter because he is paranoid about privacy.

Reader Interactions

Comments

  1. Marvin the Martian

    November 9, 2012

    Logging in as admin, my ‘update’ icon first thinks 1-2sec then shows a tickmark ‘up to date’. Clicking it, it says [copypasta:] “Joomla! Update
    No updates available
    You already have the latest Joomla! version, 2.5.7.”

    So what am I doing wrong?

    • bay area jenn

      November 10, 2012

      hover over components and click on “joomla update” – what happens then?

  2. hopy

    May 3, 2013

    I are upgrading, hope new version will run better

  3. Y8

    May 12, 2013

    Many people assume there is nothing to writing a piece of writing, however they’re not professionals.

  4. Friv 4

    May 12, 2013

    This article was therefore smart. It undoubtedly shows that you just spent plenty of your time in analysis to provide such a fine article. Thank you.

  5. Friv 3

    May 12, 2013

    I’ve browse plenty of on-line articles on this subject of late. Yours is that the only 1 that basically created sense to ME. Thanks a bunch.

  6. Yepi Friv

    May 13, 2013

    I got so involved in your article that i couldn’t even produce myself
    quit reading. thanks for producing such nice quality work.

  7. Friv 2

    June 8, 2013

    Thanks for let me know it. It is very helpful

  8. Minecraft Jugar

    September 7, 2013

    Right on! And remember, the leading cause for website compromises is outdated software! So as a website owner, you have to do your part to minimize risk and keep your site (and your users) safe.

  9. Para Friv

    October 1, 2013

    Right on! And remember, the leading cause for website compromises is outdated software
    Thanks for let me know it. It is very helpful

Primary Sidebar

Socialize With Sucuri

We're actively engaged across multiple platforms. Follow us and let's connect!

  • Facebook
  • Twitter
  • LinkedIn
  • YouTube
  • Instagram
  • RSS Feed

Joomla Security Guide

How to Clean a Hacked Website Guide

Join Over 20,000 Subscribers!

Footer

Products

  • Website Firewall
  • Website AntiVirus
  • Website Backups
  • WordPress Security
  • Enterprise Services

Solutions

  • DDos Protection
  • Malware Detection
  • Malware Removal
  • Malware Prevention
  • Blacklist Removal

Support

  • Blog
  • Knowledge Base
  • SiteCheck
  • Research Labs
  • FAQ

Company

  • About
  • Media
  • Events
  • Employment
  • Contact
  • Testimonials
  • Facebook
  • Twitter
  • LinkedIn
  • Instagram

Customer Login

Sucuri Home

  • Terms of Use
  • Privacy Policy
  • Frequently Asked Questions

© 2021 Sucuri Inc. All rights reserved

Sucuri Cookie Policy
See our policy>>

Our website uses cookies, which help us to improve our site and enables us to deliver the best possible service and customer experience.