PT-2020-17368 · Open Source Matters · Joomla!

Benjamin Trenkle

+1

·

Published

2020-12-27

·

Updated

2025-04-03

·

CVE-2020-35616

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions Joomla! versions 1.7.0 through 3.9.22
Description An issue was discovered in Joomla! due to a lack of input validation while handling ACL rulesets, which can cause write ACL violations.
Recommendations For versions 1.7.0 through 3.9.22, update to a version that contains a fix for this issue. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

RCE

Weakness Enumeration

Related Identifiers

BIT-JOOMLA-2020-35616
CVE-2020-35616

Affected Products

Joomla!