Description
A critical vulnerability was reported to the VirtueMart team. This vulnerability could be used by a malicious user to easily gain Super-Admin privileges on your website. The bug was patched and the version 2.6.10 (stable version) and 2.9.9b (in RC state) fixes this issue.
Remediation
Upgrade to the latest version of VirtueMart for Joomla! (this issue was fixed in v2.6.10).
References
Related Vulnerabilities
PHP Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2010-3062)
PrestaShop Unrestricted Upload of File with Dangerous Type Vulnerability (CVE-2018-19126)
WordPress Plugin WooCommerce Open Redirect (3.7.0)
Jenkins Improper Restriction of Rendered UI Layers or Frames Vulnerability (CVE-2020-2105)
OpenSSL NULL Pointer Dereference Vulnerability (CVE-2008-1672)