PT-2020-11995 · Open Source Matters · Joomla!

Hoang Kien

·

Published

2020-03-16

·

Updated

2025-04-03

·

CVE-2020-10239

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Joomla! versions prior to 3.9.16
Description An issue was discovered that allows incorrect access control in the SQL fieldtype of com fields, enabling access for non-superadmin users.
Recommendations For versions prior to 3.9.16, update to version 3.9.16 or later to resolve the issue.

Exploit

Fix

Incorrect Authorization

Weakness Enumeration

Related Identifiers

BIT-JOOMLA-2020-10239
CVE-2020-10239

Affected Products

Joomla!