First published: Tue Jan 28 2020(Updated: )
An issue was discovered in Joomla! before 3.9.15. A missing CSRF token check in the LESS compiler of com_templates causes a CSRF vulnerability.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Joomla | >=3.0.0<3.9.15 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-8420 is classified as a high severity vulnerability due to its potential to allow unauthorized actions through CSRF attacks.
To fix CVE-2020-8420, upgrade your Joomla! installation to version 3.9.15 or later.
CVE-2020-8420 is caused by a missing CSRF token check in the LESS compiler of com_templates in Joomla!.
CVE-2020-8420 affects Joomla! versions prior to 3.9.15.
CVE-2020-8420 is a Cross-Site Request Forgery (CSRF) vulnerability.