First published: Mon Dec 28 2020(Updated: )
An issue was discovered in Joomla! 3.9.0 through 3.9.22. Improper handling of the username leads to a user enumeration attack vector in the backend login page.
Credit: security@joomla.org
Affected Software | Affected Version | How to fix |
---|---|---|
Joomla Joomla\! | >=3.9.0<=3.9.22 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-35614 is a vulnerability in Joomla! 3.9.0 through 3.9.22 that allows for a user enumeration attack vector in the backend login page.
CVE-2020-35614 has a severity value of 5.3, indicating a medium severity.
CVE-2020-35614 affects Joomla! versions 3.9.0 through 3.9.22.
To fix CVE-2020-35614, update Joomla! to a version beyond 3.9.22.
You can find more information about CVE-2020-35614 in the Joomla! security centre: https://developer.joomla.org/security-centre/832-20201105-core-user-enumeration-in-backend-login.html