PT-2021-16930 · Joomla · Joomla!

Atik Islam

+5

·

Published

2021-07-07

·

Updated

2025-04-03

·

CVE-2021-26037

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions Joomla! versions 2.5.0 through 3.9.27
Description An issue was discovered in the CMS functions where existing user sessions were not properly terminated when a user's password was changed or the user was blocked.
Recommendations For Joomla! versions 2.5.0 through 3.9.27, update to a version that properly handles user session termination upon password change or user blockage. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Insufficient Session Expiration

Weakness Enumeration

Related Identifiers

BIT-JOOMLA-2021-26037
CVE-2021-26037

Affected Products

Joomla!