CVE-2020-35610: [20201101] - Core - com_finder ignores access levels on autosuggest
Published Dec 28, 2020
·Updated
An issue was discovered in Joomla! 2.5.0 through 3.9.22. The autosuggestion feature of comfinder did not respect the access level of the corresponding terms.
Affected Software
1 affected component
Joomla Joomla\!>=2.5.0<=3.9.22
Event History
Dec 28, 2020
CVE Published
via MITRE·07:39 PM
Data Sourced
via MITRE·07:39 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2020-35610.
2
What is the severity level of CVE-2020-35610?
The severity level of CVE-2020-35610 is high with a severity value of 7.5.
3
Which versions of Joomla are affected by CVE-2020-35610?
Joomla versions 2.5.0 through 3.9.22 are affected by CVE-2020-35610.
4
What is the impact of CVE-2020-35610?
CVE-2020-35610 allows unauthorized users to access restricted information through the autosuggestion feature of com_finder in Joomla.
5
Is there a fix available for CVE-2020-35610?
Yes, Joomla has released a security patch to fix CVE-2020-35610. It is recommended to update to the latest version of Joomla.