PT-2021-16933 · Joomla · Joomla!

Maverick

·

Published

2021-08-24

·

Updated

2025-04-03

·

CVE-2021-26040

CVSS v3.1

9.1

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H
Name of the Vulnerable Software and Affected Versions Joomla! version 4.0.0
Description An issue was discovered in the media manager, which does not correctly check the user's permissions before executing a file deletion command.
Recommendations For Joomla! version 4.0.0, update to a version that includes the fix for this issue, as the media manager's incorrect permission checking can lead to unauthorized file deletion. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Incorrect Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BIT-JOOMLA-2021-26040
CVE-2021-26040

Affected Products

Joomla!