Loading
The register method in the UsersModelRegistration class in controllers/user.php in the Users component in Joomla! before 3.6.4, when registration has been disabled, allows remote attackers to create user accounts by leveraging failure to check the Allow User Registration configuration setting.
Use CWE-20, Joomla vendor hub and Joomla\! product page to widen CVE-2016-8870 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2009-4789, CVE-2010-1470 and CVE-2010-0694 for nearby disclosures in the same product family.