CVE-2020-13760: CSRF
Published Jun 2, 2020
·Updated
In Joomla! before 3.9.19, missing token checks in compostinstall lead to CSRF.
Affected Software
12 affected components
Joomla Joomla\!>=3.7.1<3.9.19
Joomla Joomla\!=3.7.0
Joomla Joomla\!=3.7.0-alpha1
Joomla Joomla\!=3.7.0-alpha2
Joomla Joomla\!=3.7.0-beta1
Joomla Joomla\!=3.7.0-beta2
Joomla Joomla\!=3.7.0-beta3
Joomla Joomla\!=3.7.0-beta4
Joomla Joomla\!=3.7.0-rc1
Joomla Joomla\!=3.7.0-rc2
Joomla Joomla\!=3.7.0-rc3
Joomla Joomla\!=3.7.0-rc4
Event History
Jun 2, 2020
CVE Published
via MITRE·07:25 PM
Data Sourced
via MITRE·07:25 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2020-13760?
CVE-2020-13760 is classified as a medium severity vulnerability due to the potential for CSRF attacks.
2
How do I fix CVE-2020-13760?
To fix CVE-2020-13760, upgrade your Joomla! installation to version 3.9.19 or later.
3
Which versions of Joomla! are affected by CVE-2020-13760?
CVE-2020-13760 affects Joomla! versions before 3.9.19, including all versions from 3.7.1 up to 3.9.18.
4
What type of vulnerability is CVE-2020-13760?
CVE-2020-13760 is a Cross-Site Request Forgery (CSRF) vulnerability due to missing token checks.
5
Is there a risk of data exposure with CVE-2020-13760?
Yes, if exploited, CVE-2020-13760 could allow unauthorized actions on behalf of the user, potentially leading to data exposure.