How to fix the security vulnerability affecting 1 in every 10 Joomla sites
Thursday, 19 December 2013 / News
Yesterday we were informed of a very serious security vulnerability in eXtplorer — a popular file management utility for Joomla.
After some research, we now know that on up to 1 in every 10 Joomla websites may be subject to this vulnerability. Thankfully, there are a two easy ways to fix the issue.
Standard Joomla sites
- Login to site and look for eXtplorer in the Components menu
- CRITICAL STEP - If you find it, Uninstall immediately
- If you still require this extension, install version 2.1.5 or later
- If removing and installing are not options for you, there are some alternate patches available also.
Watchful-enhanced Joomla sites
Sites that use Watchful can save a tonne of time identifying and fixing affected sites without having to individually log into any sites at all, using the custom uninstall tool we have created for our subscribers.
- Use the search tool in the Watchful Dashboard to identify any sites that have eXtplorer.
- Only sites with eXtplorer installed are now listed, simply check the top Select All checkbox and then click the Install button in the toolbar.
- To remove eXtplorer from all your sites, paste the URL below into the field provided and then click Install All. This will remove eXtplorer from all your sites in one click.
- Now install the latest patched version (at time of this writing) of eXtplorer in the same way by using the URL below.
- To confirm installation, return to the Watchful Dashboard and validate the affected sites.
- For websites built on Joomla 1.5 or earlier, you can identify sites with eXtplorer, but fixing the site must be done manually as described above.
Three more easy security tips
Additional reading from your Watchful team that can make your Joomla Site safer
- 3 Joomla security tips to protect against brute force attacks
- Joomla 1.5 security patch made easy to install
- Monitor critical file for unauthorized changes