Description
Joomla! Core is prone to a race condition, where a session which was expected to be destroyed would be recreated. Attackers can exploit this issue to perform unauthorized actions. Joomla! Core versions 3.x.x ranging from 3.0.0 and up to and including 3.8.7 are vulnerable.
Remediation
Update to Joomla! Core version 3.8.8 or latest
References
Related Vulnerabilities
phpBB Improper Control of Generation of Code ('Code Injection') Vulnerability (CVE-2019-16108)
WordPress Plugin WooCommerce Checkout Manager Cross-Site Request Forgery (4.3)
WordPress Plugin is_human() 'type' Parameter Remote Command Injection (1.4.2)
WordPress Plugin Simple Mail Address Encoder Cross-Site Scripting (1.6.1)
WordPress Plugin Pixabay Images Multiple Vulnerabilities (2.3)