Security Bypass Vulnerability in Joomla! Core by Joomla
CVE-2010-1435

9.8CRITICAL

Key Information:

Vendor
Joomla
Status
Vendor
CVE Published:
21 June 2021

Summary

The Joomla! Core is impacted by a security bypass vulnerability that can be exploited to perform unauthorized actions. Attackers can leverage this weakness in conjunction with an existing SQL injection flaw to access password reset tokens stored in the database. It’s crucial for users of Joomla! Core versions between 1.5.0 and 1.5.15 to apply necessary patches to safeguard against this exploit.

Affected Version(s)

Joomla Joomla core from 1.5.0 up to and including 1.5.15

References

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.