CVE-2024-27187: [20240804] - Core - Improper ACL for backend profile view
Published Aug 20, 2024
·Updated
Improper Access Controls allows backend users to overwrite their username when disallowed.
Affected Software
2 affected components
Joomla Joomla\!>=4.0.0<4.4.7
Joomla Joomla\!>=5.0.0<5.1.3
Event History
Aug 20, 2024
CVE Published
via MITRE·04:03 PM
Data Sourced
via MITRE·04:03 PM
DescriptionWeakness
Data Sourced
via NVD·04:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-27187?
CVE-2024-27187 is classified as a medium severity vulnerability.
2
How do I fix CVE-2024-27187?
To fix CVE-2024-27187, ensure your Joomla installation is updated to version 4.4.8 or later for version 4.x, or 5.1.4 or later for version 5.x.
3
Who is affected by CVE-2024-27187?
CVE-2024-27187 affects Joomla installations versions between 4.0.0 and 4.4.7 and versions between 5.0.0 and 5.1.3.
4
What type of vulnerability is CVE-2024-27187?
CVE-2024-27187 is an improper access control vulnerability that allows backend users to overwrite their username.
5
When was CVE-2024-27187 disclosed?
CVE-2024-27187 was disclosed on August 4, 2024.