Description
Joomla! Core is prone to a security bypass vulnerability. Exploiting this issue may allow attackers to perform otherwise restricted actions and subsequently manipulate the update server URL. Joomla! Core versions 3.x.x ranging from 3.8.13 and up to and including 3.9.6 are vulnerable.
Remediation
Update to Joomla! Core version 3.9.7 or latest
References
Related Vulnerabilities
Chamilo Server-Side Request Forgery (SSRF) Vulnerability (CVE-2023-34959)
WordPress Plugin Tutor LMS-eLearning and online course solution Cross-Site Request Forgery (1.5.2)
Apache Traffic Server CVE-2015-5206 Vulnerability (CVE-2015-5206)
WordPress Plugin Anti Spam Protection without CAPTCHA powered by Keypic Security Bypass (2.1.2)
WordPress Plugin SyntaxHighlighter Evolved Cross-Site Scripting (3.5.0)