Joomla!是一套使用在Joomla!内容管理系统中的论坛组件。 Joomla! CMS 2.5.0 - 3.9.27存在代码问题漏洞,该漏洞源于修改用户密码或阻止用户帐户时,会话过期时间不足。远程的未经身份验证的攻击者可利用该漏洞获得或猜测会话令牌,并获得对属于另一个用户的会话的未经授权的访问。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Joomla! Project | Joomla! CMS | 2.5.0-3.9.27 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2021-26035 | [20210701] - Core - XSS in JForm Rules field | |
| CVE-2021-26036 | [20210702] - Core - DoS through usergroup table manipulation | |
| CVE-2021-26038 | [20210704] - Core - Privilege escalation through com_installer | |
| CVE-2021-26039 | [20210705] - Core - XSS in com_media imagelist |
No comments yet