

This vulnerability can be exploited from the back-end of joomla (/administrator), but it also can be exploited by using a simple Registered account.
4. Vulnerable Versions
5. Solution
6. Vulnerability Timeline
- September 01, 2015 — Bug reported to Joobi
- September 02, 2015 — Jnews’s team replied asking more info
- September 24, 2015 — Jnews’s team releases a new version
- October 28, 2015 — Public disclosure