Italian security researcher Alessandro Groppo has issued a zero-day vulnerability for Joomla. The vulnerability is easy to exploit and the code of attack proof-of-concept was published online. It is a PHP object injection that, within certain situations, can lead to remote code execution. In December 2015, when the vulnerability was found, hackers used it in the wild to take over pages. The good news is that the issue at the root of Groppos. issue seems to have been addressed since CVE-2015-8562 has been patched.”]
Source: https://hackercombat.com/zero-day-issued-for-old-cms-online-proof-of-concept-code-available/

