First published: Wed Jul 07 2021(Updated: )
An issue was discovered in Joomla! 2.5.0 through 3.9.27. CMS functions did not properly termine existing user sessions when a user's password was changed or the user was blocked.
Credit: security@joomla.org
Affected Software | Affected Version | How to fix |
---|---|---|
Joomla Joomla\! | >=2.5.0<=3.9.27 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID of this issue is CVE-2021-26037.
The affected software is Joomla! version 2.5.0 through 3.9.27.
The severity of CVE-2021-26037 is medium, with a severity value of 5.3.
This vulnerability can be exploited by an attacker who has access to a user account on the Joomla! website.
Yes, a fix is available for this vulnerability. It is recommended to update to a patched version of Joomla!.