PT-2020-17366 · Joomla · Joomla!

Phil Taylor

·

Published

2020-12-28

·

Updated

2025-04-03

·

CVE-2020-35614

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Joomla! versions 3.9.0 through 3.9.22
Description An issue was discovered that leads to a user enumeration attack vector in the backend login page due to improper handling of the username.
Recommendations For Joomla! versions 3.9.0 through 3.9.22, update to a version that fixes the improper handling of the username to prevent user enumeration attacks.

Fix

Related Identifiers

BIT-JOOMLA-2020-35614
CVE-2020-35614

Affected Products

Joomla!