Monday, July 12, 2021

Joomla!: [20210704] - Core - Privilege escalation through com_installer (CVE-2021-26038)

Description
An issue was discovered in Joomla! 2.5.0 through 3.9.27. Install action in com_installer lack the required hardcoded ACL checks for superusers. A default system is not affected cause the default ACL for com_installer is limited to super users already.
Solution(s)
  • joomla-upgrade-3_9_28


  • References
  • https://attackerkb.com/topics/cve-2021-26038
  • CVE - 2021-26038
  • http://developer.joomla.org/security-centre/859-20210704-core-privilege-escalation-through-com-installer.html




  •  

    Copyright © 2020 Cyber Details - Vulnerability Database™

    Thanks for everything Templateism - You should have written the code a little more complicated