QID 154087
Date Published: 2021-09-13
QID 154087: Joomla! Core - CSRF and User Enumeration Vulnerability
Joomla is a free and open-source content management system written in PHP. A Cross-Site Resource Forgery and a User Enumeration vulnerability was discovered in the current installation of Joomla!. This issue exists due to a missing token check in the 'emailexport' feature of 'com_privacy' and the later, due to Improper handling of the username in the backend login page. This affects Joomla! versions through 3.9.22.
Affected Versions:
Joomla! 3.9.0 - 3.9.22
Upon successful exploitation of a CSRF vulnerability, victim can be tricked into performing certain action without knowledge, such as deleting/adding any record. The other vulnerability would allow an attacker to successfully enumerate the users of the application, affecting the Confidentiality of the application.
CVEs related to QID 154087
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| 20201105 |
|
||
| 20201105 |
|