Security Announcement for Joomla Version 3.7.1

  • Saturday, 31st March, 2018
  • 20:26pm
The Joomla Security Strike team has been following up on the critical security vulnerability patched last week. Since the recent update it has become clear that the root cause is a bug in PHP itself. This was fixed by PHP in September of this year (2015) with the releases of PHP 5.4.45, 5.5.29, 5.6.13 (N.B. Fixed in all versions of PHP 7 and has been backported in some specific Linux LTS versions of PHP 5.3).

The only Joomla sites affected by this bug are those which are hosted on vulnerable versions of PHP. We are aware that not all hosts keep their PHP installations up to date so we are releasing a Joomla Update later today which contains additional protection for those users. We do of course recommend that all users apply this update as soon as possible.
« Back