Description
An issue was discovered in Joomla! 2.5.0 through 3.10.6 & 4.0.0 through 4.1.0. A user row was not bound to a specific authentication mechanism which could under very special circumstances allow an account takeover.
Remediation
References
Related Vulnerabilities
Jboss EAP Loop with Unreachable Exit Condition ('Infinite Loop') Vulnerability (CVE-2018-1041)
Zope Web Application Server Other Vulnerability (CVE-2007-0240)
WordPress Plugin Flat Preloader Cross-Site Scripting (1.5.4)
WordPress Plugin PS PHPCaptcha WP Denial of Service (1.1.0)
YetiForce CRM Improper Input Validation Vulnerability (CVE-2021-4111)