Description
Joomla! Core is prone to a security bypass vulnerability. Exploiting this issue may allow attackers to perform otherwise restricted actions and subsequently gain read access to data which should be access restricted to users with edit_own level. Joomla! Core versions ranging from 1.6.0 and up to and including 3.6.0 are vulnerable.
Remediation
Update to Joomla! Core version 3.6.1 or latest
References
Related Vulnerabilities
IBM RTC Improper Restriction of XML External Entity Reference Vulnerability (CVE-2016-0284)
Craft CMS Unrestricted Upload of File with Dangerous Type Vulnerability (CVE-2018-3814)
WordPress Plugin Simple:Press-WordPress Forum Arbitrary File Upload (6.6.0)
WordPress Plugin Fluid Responsive Slideshow Multiple Vulnerabilities (2.2.6)