CVE-2013-3242: Joomla!

Medium severity, CVSS 5.5. EPSS: 4.8% chance of exploitation in the next 30 days.

plugins/system/remember/remember.php in Joomla! 2.5.x before 2.5.10 and 3.0.x before 3.0.4 does not properly handle an object obtained by unserializing a cookie, which allows remote authenticated users to conduct PHP object injection attacks and cause a denial of service via unspecified vectors.

Affected products

  • Joomla! Joomla!: version 3.0.0 only; version 3.0.1 only; version 3.0.2 only; version 3.0.3 only; version 2.5.0 only; version 2.5.1 only; …

Published 2013-05-03. Last modified 2026-06-16.