First published: Wed Jul 15 2020(Updated: )
An issue was discovered in Joomla! through 3.9.19. A missing token check in the ajax_install endpoint of com_installer causes a CSRF vulnerability.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Joomla Joomla\! | >=3.7.0<=3.9.19 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-15700 is a CSRF vulnerability in Joomla! through version 3.9.19 caused by a missing token check in the ajax_install endpoint of com_installer.
CVE-2020-15700 has a severity score of 6.3, classified as a medium severity vulnerability.
To mitigate CVE-2020-15700, ensure to implement proper token checks in the ajax_install endpoint of com_installer in Joomla.