CVE-2019-10946: High severity joomla vulnerability
Published Apr 10, 2019
·Updated
An issue was discovered in Joomla! before 3.9.5. The "refresh list of helpsites" endpoint of comusers lacks access checks, allowing calls from unauthenticated users.
Affected Software
1 affected component
Joomla Joomla\!>=3.2.0<=3.9.4
Event History
Apr 10, 2019
CVE Published
via MITRE·06:08 PM
Data Sourced
via MITRE·06:08 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2019-10946?
CVE-2019-10946 is classified as a medium-severity vulnerability due to the lack of access controls.
2
How do I fix CVE-2019-10946?
To fix CVE-2019-10946, update your Joomla! installation to version 3.9.5 or later.
3
Who is affected by CVE-2019-10946?
CVE-2019-10946 affects Joomla! versions prior to 3.9.5.
4
What are the potential risks of CVE-2019-10946?
The potential risks of CVE-2019-10946 include unauthorized access to the helpsites endpoint by unauthenticated users.
5
What functionality is compromised due to CVE-2019-10946?
CVE-2019-10946 compromises the security of the 'refresh list of helpsites' functionality in Joomla!.