Description
The register method in the UsersModelRegistration class in controllers/user.php in the Users component in Joomla! before 3.6.4 allows remote attackers to gain privileges by leveraging incorrect use of unfiltered data when registering on a site.
Remediation
References
Related Vulnerabilities
WordPress 5.2.x Multiple Vulnerabilities (5.2 - 5.2.15)
PrestaShop Improper Privilege Management Vulnerability (CVE-2013-6295)
Joomla! Core 3.x.x Multiple Vulnerabilities (3.0.0 - 3.6.4)
MySQL NULL Pointer Dereference Vulnerability (CVE-2020-1971)
Jboss EAP Improper Input Validation Vulnerability (CVE-2019-12400)