Description
An issue was discovered in Joomla! 2.5.0 through 3.9.27. Install action in com_installer lack the required hardcoded ACL checks for superusers. A default system is not affected cause the default ACL for com_installer is limited to super users already.
Remediation
References
Related Vulnerabilities
WordPress Plugin GS Filterable Portfolio Cross-Site Scripting (1.6.0)
WordPress Plugin WP Google Maps Cross-Site Request Forgery (7.11.27)
WordPress Plugin Church Admin 'id' Parameter Cross-Site Scripting (0.33.4.5)
Moodle URL Redirection to Untrusted Site ('Open Redirect') Vulnerability (CVE-2019-10133)