Description
An issue was discovered in Joomla! before 3.9.16. Missing token checks in the image actions of com_templates lead to CSRF.
Remediation
References
Related Vulnerabilities
WordPress Plugin Style Kits-Advanced Theme Styles for Elementor Cross-Site Request Forgery (1.8.0)
Joomla Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2015-5397)
WordPress Plugin WooCommerce Checkout Manager Multiple Unspecified Vulnerabilities (3.6.9)
Joomla Insufficient Session Expiration Vulnerability (CVE-2021-26037)