Description
Sucuri reported a vulnerability in Akeeba Backup for Joomla! that could allow an attacker to list and download backups created with the Akeeba extension. This vulnerability is present on Joomla websites running Akeeba that have the "Enable front-end and remote backup" option activated.
Remediation
Upgrade to the latest version of Akeeba Backup for Joomla!.
References
Related Vulnerabilities
WordPress Plugin WatchTowerHQ Security Bypass (3.6.15)
WordPress Plugin BP Group Documents Security Bypass (1.10)
WordPress Plugin TheCartPress eCommerce Shopping Cart Order Information Security Bypass (1.1.9.2)
WordPress Plugin InstaWP Connect-1-click WP Staging & Migration Security Bypass (0.1.0.8)