Description
The CMS installer in Joomla! before 3.7.4 does not verify a user's ownership of a webspace, which allows remote authenticated users to gain control of the target application by leveraging Certificate Transparency logs.
Remediation
References
Related Vulnerabilities
WordPress Plugin Gravity Forms Information Disclosure (2.4.8)
WordPress Plugin User Meta Manager Multiple Vulnerabilities (3.4.6)
Jenkins Permissions, Privileges, and Access Controls Vulnerability (CVE-2014-2058)
Apache Tomcat Permissions, Privileges, and Access Controls Vulnerability (CVE-2012-3546)
WordPress Plugin WP Job Manager PHP Object Injection (1.31.2)