First published: Tue May 25 2021(Updated: )
An issue was discovered in Joomla! 3.0.0 through 3.9.26. A missing token check causes a CSRF vulnerability in the AJAX reordering endpoint.
Credit: security@joomla.org
Affected Software | Affected Version | How to fix |
---|---|---|
Joomla Joomla\! | >=3.0.0<=3.9.26 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2021-26033.
The severity of CVE-2021-26033 is medium.
CVE-2021-26033 affects Joomla! versions 3.0.0 through 3.9.26.
The CWE ID for CVE-2021-26033 is CWE-352.
Yes, Joomla! has released a fix for CVE-2021-26033. It is recommended to update to the latest version.