Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
[20210704] - Core - Privilege escalation through com_installer
Vulnerability Description
An issue was discovered in Joomla! 2.5.0 through 3.9.27. Install action in com_installer lack the required hardcoded ACL checks for superusers. A default system is not affected cause the default ACL for com_installer is limited to super users already.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Joomla! 代码问题漏洞
Vulnerability Description
Joomla!是一套使用在Joomla!内容管理系统中的论坛组件。 Joomla! CMS 2.5.0 - 3.9.27存在代码问题漏洞,该漏洞源于com_installer 中的安装操作缺少对超级用户所需的硬编码 ACL 检查。
CVSS Information
N/A
Vulnerability Type
N/A