A critical flaw in Joomla! tracked as CVE-2015-8562 allowed unauthenticated attackers to achieve remote code execution by sending crafted HTTP headers, including User-Agent, to vulnerable sites. The bug affected Joomla! versions 1.5.0 through 3.4.5 and was fixed in 3.4.6. Researchers reported that exploitation was already occurring in the wild before the patch was released, with attackers abusing Joomla!'s session handling to write malicious serialized data into the backend MySQL session store and trigger code execution on a follow-up request.
The exploit chain relied on multiple conditions: Joomla! stored session data in MySQL text fields, MySQL could silently truncate input containing 4-byte UTF-8 characters under configurations such as utf8_general_ci, and PHP session decoding behavior associated with CVE-2015-6835 could turn the truncated data into attacker-controlled objects. The injected object chain then reached Joomla! components including JDatabaseDriverMysqli and SimplePie, ultimately invoking dangerous code paths such as assert(). Recommended mitigations included upgrading Joomla! and PHP, applying distribution patches, using utf8mb4 where appropriate, and enabling stricter MySQL SQL modes to prevent silent truncation.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
3 events from the most recent confirmed update back to the earliest known activity.
Joomla! released version 3.4.6 on December 14, 2015, patching the unauthenticated remote code execution vulnerability CVE-2015-8562 affecting versions 1.5.0 through 3.4.5.
Sucuri observed broad attacks exploiting the Joomla! flaw against its websites and honeypots between December 13 and 14, 2015. Separate reporting also noted that exploitation was already occurring in the wild.
Sucuri stated that exploit code for the Joomla! vulnerability was already circulating on December 12, 2015, indicating pre-patch weaponization.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.