CVE-2020-10240: Input Validation
Published Mar 16, 2020
·Updated
An issue was discovered in Joomla! before 3.9.16. Missing length checks in the user table can lead to the creation of users with duplicate usernames and/or email addresses.
Affected Software
1 affected component
Joomla Joomla\!>=3.0.0<3.9.16
Event History
Mar 16, 2020
CVE Published
via MITRE·03:46 PM
Data Sourced
via MITRE·03:46 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2020-10240?
CVE-2020-10240 has been classified as a medium severity vulnerability.
2
How do I fix CVE-2020-10240?
To fix CVE-2020-10240, upgrade Joomla! to version 3.9.16 or later.
3
What impact does CVE-2020-10240 have on Joomla! installations?
CVE-2020-10240 can allow the creation of users with duplicate usernames and email addresses, leading to potential authentication issues.
4
Which versions of Joomla! are affected by CVE-2020-10240?
Joomla! versions prior to 3.9.16 are affected by CVE-2020-10240.
5
Is there a workaround for CVE-2020-10240?
There are no official workarounds for CVE-2020-10240; updating to the latest version is recommended.