MFA management system vulnerability: Sessions not properly terminated
CVE-2024-21722

Currently unrated

Key Information:

Vendor
Joomla
Status
Joomla! Cms
Vendor
CVE Published:
29 February 2024

Summary

The MFA management features did not properly terminate existing user sessions when a user's MFA methods have been modified.

Affected Version(s)

Joomla! CMS 3.2.0-3.10.14

Joomla! CMS 4.0.0-4.4.2

Joomla! CMS 5.0.0-5.0.2

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Collectors

NVD DatabaseMitre Database

Credit

Carsten Schmitz
.