Astroid Framwork gehacked

Astroid Framwork gehacked was created by joflatz

Posted 7 hours 48 minutes ago #36392
The Astroid framework has reportedly been hacked for numerous Joomla users. A colleague from Vienna just alerted me to this.

Apparently, it can be identified by unusual plugins, such as payload.

Does anyone in the JoomlaPlates community know anything about this?
by joflatz

Please Log in or Create an account to join the conversation.

Replied by joomlaplates on topic Astroid Framwork gehacked

Posted 6 hours 31 minutes ago #36393
The reported vulnerability has been CONFIRMED and FIXED. The Astroid Framework for Joomla had a critical security flaw where admin-only AJAX endpoints relied solely on
Code:
Session::checkToken()
for authentication. This token validates CSRF protection but does not verify that a valid admin session exists. An unauthenticated attacker could obtain a token from the admin login form and use it to perform privileged actions.

If .htaccess blocks access to /administrator/, the attacker cannot reach the login page and therefore cannot obtain the token. In that case, the vulnerability is effectively not exploitable from outside.
Please protect your backend with .htaccess
PS We are working on a fix this night

Please Log in or Create an account to join the conversation.

Replied by joflatz on topic Astroid Framwork gehacked

Posted 2 hours 5 minutes ago #36395
 Thanks for the reply, I'm looking forward to the patch like probably many other Astroid users - currently all my client sites are blocked.
by joflatz

Please Log in or Create an account to join the conversation.

Installations-Service

Don´t waste your time, we install your purchased Template
with the "Demo Content" within the next 24 hours.

Buy Now - 59€

JoomlaPlates

Professional Joomla Templates with rich documentation and support since 2008. 60+ templates for Joomla 5 & 6.

Joomla 4 Joomla 5 Joomla 6
Contact & Legal
  • support@joomlaplates.com
  • Support Team
  • Mon-Fri: 9:00-18:00 CET

© JoomlaPlates. All rights reserved. 2008 - 2026

JoomlaPlates is not affiliated with or endorsed by the Joomla! Project. Joomla! is a registered trademark of Open Source Matters, Inc.