PT-2021-16927 · Joomla · Joomla!

Phil Taylor

·

Published

2021-05-26

·

Updated

2025-04-03

·

CVE-2021-26034

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions Joomla! versions 3.0.0 through 3.9.26
Description A missing token check causes a CSRF issue in data download endpoints in com banners and com sysinfo. This allows for potential exploitation.
Recommendations For Joomla! versions 3.0.0 through 3.9.26, consider disabling the data download endpoints in com banners and com sysinfo as a temporary workaround until a patch is available. Restrict access to these components to minimize the risk of exploitation.

Fix

CSRF

Weakness Enumeration

Related Identifiers

BIT-JOOMLA-2021-26034
CVE-2021-26034

Affected Products

Joomla!