MFA management system vulnerability: Sessions not properly terminated

CVE-2024-21722
Currently unrated 🤨

Key Information

Vendor
Joomla
Status
Joomla! Cms
Vendor
CVE Published:
29 February 2024

Summary

The MFA management features did not properly terminate existing user sessions when a user's MFA methods have been modified.

Affected Version(s)

Joomla! CMS = 3.2.0-3.10.14

Joomla! CMS = 4.0.0-4.4.2

Joomla! CMS = 5.0.0-5.0.2

Timeline

  • Vulnerability published.

  • Vulnerability Reserved.

Collectors

NVD DatabaseMitre Database

Credit

Carsten Schmitz
.