An issue was discovered in Joomla! 2.5.0 through 3.10.6 & 4.0.0 through 4.1.0. A user row was not bound to a specific authentication mechanism which could under very special circumstances allow an account takeover.
2022-03-30T16:15:11.527
2024-11-21T06:49:16.267
Modified
CVSSv3.1: 9.8 (CRITICAL)
AV:N/AC:M/Au:N/C:P/I:P/A:P
8.6
6.4
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | joomla | joomla\! | ≤ 3.10.6 | Yes |
Application | joomla | joomla\! | ≤ 4.1.0 | Yes |