PT-2020-14595 · Open Source Matters · Joomla!

Bui Duc Anh Khoa

·

Published

2020-07-15

·

Updated

2025-04-03

·

CVE-2020-15700

CVSS v2.0

6.8

Medium

VectorAV:N/AC:M/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Joomla! versions prior to 3.9.20
Description A missing token check in the "ajax install" endpoint of com installer causes a CSRF issue.
Recommendations For versions prior to 3.9.20, update to version 3.9.20 or later to resolve the issue.

Fix

CSRF

Weakness Enumeration

Related Identifiers

BIT-JOOMLA-2020-15700
CVE-2020-15700

Affected Products

Joomla!