Description
Joomla! Core is prone to a security bypass vulnerability. Exploiting this issue may allow attackers to perform otherwise restricted actions and subsequently gain read access to data which should be access restricted to users with edit_own level. Joomla! Core versions ranging from 1.6.0 and up to and including 3.6.0 are vulnerable.
Remediation
Update to Joomla! Core version 3.6.1 or latest
References
Related Vulnerabilities
WordPress Plugin WP Attachment Export Arbitrary File Download (0.2.3)
WordPress Plugin FavIcon Switcher Cross-Site Request Forgery (1.2.11)
Play Framework Improper Input Validation Vulnerability (CVE-2015-2156)
MySQL CVE-2018-3123 Vulnerability (CVE-2018-3123)
phpMyAdmin 7PK - Security Features Vulnerability (CVE-2016-1927)