Description
plugins/system/remember/remember.php in Joomla! 2.5.x before 2.5.10 and 3.0.x before 3.0.4 does not properly handle an object obtained by unserializing a cookie, which allows remote authenticated users to conduct PHP object injection attacks and cause a denial of service via unspecified vectors.
Remediation
References
Related Vulnerabilities
Envoy Proxy Incorrect Authorization Vulnerability (CVE-2021-32779)
Next.js Improper Check for Unusual or Exceptional Conditions Vulnerability (CVE-2022-36046)
WebLogic Inclusion of Functionality from Untrusted Control Sphere Vulnerability (CVE-2018-11040)
Joomla! Core 1.0.x Multiple Vulnerabilities (1.0.0 - 1.0.13)