CVE-2020-35616: [20201107] - Core - Write ACL violation in multiple core views
Published Dec 28, 2020
·Updated
An issue was discovered in Joomla! 1.7.0 through 3.9.22. Lack of input validation while handling ACL rulesets can cause write ACL violations.
Affected Software
1 affected component
Joomla Joomla\!>=1.7.0<=3.9.22
Event History
Dec 28, 2020
CVE Published
via MITRE·07:39 PM
Data Sourced
via MITRE·07:39 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the vulnerability ID for this Joomla issue?
The vulnerability ID for this Joomla issue is CVE-2020-35616.
2
What is the severity of CVE-2020-35616?
The severity of CVE-2020-35616 is high with a CVSS score of 7.5.
3
What is the description of CVE-2020-35616?
CVE-2020-35616 is a vulnerability in Joomla 1.7.0 through 3.9.22 that allows write ACL violations due to lack of input validation in handling ACL rulesets.
4
How does CVE-2020-35616 impact Joomla?
CVE-2020-35616 can result in write ACL violations, potentially allowing unauthorized users to modify or delete sensitive data in Joomla.
5
How can I fix CVE-2020-35616?
To fix CVE-2020-35616, it is recommended to update Joomla to version 3.9.23 or later, which includes a patch for this vulnerability.