Description
Joomla! Core is prone to a race condition, where a session which was expected to be destroyed would be recreated. Attackers can exploit this issue to perform unauthorized actions. Joomla! Core versions 3.x.x ranging from 3.0.0 and up to and including 3.8.7 are vulnerable.
Remediation
Update to Joomla! Core version 3.8.8 or latest
References
Related Vulnerabilities
WordPress Plugin Forminator-Contact Form, Payment Form & Custom Form Builder SQL Injection (1.29.2)
phpMyFAQ Incorrect Authorization Vulnerability (CVE-2024-22208)
WordPress Plugin Ad Swapper Cross-Site Scripting (1.0.3)
WordPress 4.8.x Cross-Site Request Forgery (4.8 - 4.8.8)
WordPress Plugin NextScripts:Social Networks Auto-Poster Security Bypass (4.3.17)