First published: Wed Apr 10 2019(Updated: )
An issue was discovered in Joomla! before 3.9.5. The "refresh list of helpsites" endpoint of com_users lacks access checks, allowing calls from unauthenticated users.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Joomla | >=3.2.0<=3.9.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-10946 is classified as a medium-severity vulnerability due to the lack of access controls.
To fix CVE-2019-10946, update your Joomla! installation to version 3.9.5 or later.
CVE-2019-10946 affects Joomla! versions prior to 3.9.5.
The potential risks of CVE-2019-10946 include unauthorized access to the helpsites endpoint by unauthenticated users.
CVE-2019-10946 compromises the security of the 'refresh list of helpsites' functionality in Joomla!.