Joomla! Core CVE-2019-10946 Access Bypass Vulnerability
BID:107832
Info
Joomla! Core CVE-2019-10946 Access Bypass Vulnerability
| Bugtraq ID: | 107832 |
| Class: | Access Validation Error |
| CVE: |
CVE-2019-10946 |
| Remote: | Yes |
| Local: | No |
| Published: | Apr 09 2019 12:00AM |
| Updated: | Apr 09 2019 12:00AM |
| Credit: | Benjamin Trenkle (JSST) |
| Vulnerable: |
Joomla Joomla! 3.9.4 Joomla Joomla! 3.9.3 Joomla Joomla! 3.9.2 Joomla Joomla! 3.9.1 Joomla Joomla! 3.9 Joomla Joomla! 3.8.13 Joomla Joomla! 3.8.12 Joomla Joomla! 3.8.11 Joomla Joomla! 3.8.10 Joomla Joomla! 3.8.9 Joomla Joomla! 3.8.8 Joomla Joomla! 3.8.7 Joomla Joomla! 3.8.6 Joomla Joomla! 3.8.5 Joomla Joomla! 3.8.4 Joomla Joomla! 3.8.3 Joomla Joomla! 3.8.2 Joomla Joomla! 3.8.1 Joomla Joomla! 3.7.3 Joomla Joomla! 3.7.2 Joomla Joomla! 3.7.1 Joomla Joomla! 3.7 Joomla Joomla! 3.6.5 Joomla Joomla! 3.5 Joomla Joomla! 3.4.7 Joomla Joomla! 3.4.6 Joomla Joomla! 3.4.4 Joomla Joomla! 3.4.3 Joomla Joomla! 3.4.2 Joomla Joomla! 3.4.1 Joomla Joomla! 3.4 Joomla Joomla! 3.3.6 Joomla Joomla! 3.3.5 Joomla Joomla! 3.3.4 Joomla Joomla! 3.3.3 Joomla Joomla! 3.3.2 Joomla Joomla! 3.3.1 Joomla Joomla! 3.3 Joomla Joomla! 3.2.6 Joomla Joomla! 3.2.5 Joomla Joomla! 3.2.4 Joomla Joomla! 3.2.3 Joomla Joomla! 3.2.2 Joomla Joomla! 3.2.1 Joomla Joomla! 3.8.0 Joomla Joomla! 3.7.5 Joomla Joomla! 3.7.4 Joomla Joomla! 3.6.4 Joomla Joomla! 3.6.3 Joomla Joomla! 3.6.1 Joomla Joomla! 3.6.0 Joomla Joomla! 3.4.5 Joomla Joomla! 3.2 |
| Not Vulnerable: |
Joomla Joomla! 3.9.5 |
Discussion
Joomla! Core CVE-2019-10946 Access Bypass Vulnerability
Joomla! Core is prone to an access-bypass vulnerability.
Attackers can exploit this issue to bypass security restrictions to perform unauthorized actions; this may aid in launching further attacks.
Joomla! 3.2.0 through 3.9.4 are vulnerable; other versions may also be affected.
Joomla! Core is prone to an access-bypass vulnerability.
Attackers can exploit this issue to bypass security restrictions to perform unauthorized actions; this may aid in launching further attacks.
Joomla! 3.2.0 through 3.9.4 are vulnerable; other versions may also be affected.
Exploit / POC
Joomla! Core CVE-2019-10946 Access Bypass Vulnerability
Currently, we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently, we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
Joomla! Core CVE-2019-10946 Access Bypass Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
Joomla! Core CVE-2019-10946 Access Bypass Vulnerability
References:
References:
- Joomla Homepage (Joomla)
- Security Announcements (joomla)