Описание
An issue was discovered in Joomla! 2.5.0 through 3.10.6 & 4.0.0 through 4.1.0. A user row was not bound to a specific authentication mechanism which could under very special circumstances allow an account takeover.
Уязвимые конфигурации
Конфигурация 1Версия от 2.5.0 (включая) до 3.10.6 (включая)Версия от 4.0.0 (включая) до 4.1.0 (включая)
Одно из
cpe:2.3:a:joomla:joomla\!:*:*:*:*:*:*:*:*
cpe:2.3:a:joomla:joomla\!:*:*:*:*:*:*:*:*
EPSS
Процентиль: 1%
0.00009
Низкий
9.8 Critical
CVSS3
6.8 Medium
CVSS2
Дефекты
CWE-287
Связанные уязвимости
CVSS3: 9.8
github
почти 4 года назад
An issue was discovered in Joomla! 2.5.0 through 3.10.6 & 4.0.0 through 4.1.0. A user row was not bound to a specific authentication mechanism which could under very special circumstances allow an account takeover.
EPSS
Процентиль: 1%
0.00009
Низкий
9.8 Critical
CVSS3
6.8 Medium
CVSS2
Дефекты
CWE-287