Joomla 4.2.7 with sample data, vulnerable to CVE-2023-23752: adding public=true to a /api/index.php/v1 request overwrites the route's public attribute, so an unauthenticated user reads the application configuration, including the database credentials, and the users.
Not startedDockercommit 00402f0x86_64 · aarch64Secret
Exploit CVE-2023-23752 to read Joomla's configuration and the database password without logging in.
The brief for this lab lives in its repository.