Description
An issue was discovered in Joomla! before 3.8.13. com_joomlaupdate allows the execution of arbitrary code. The default ACL config enabled the ability of Administrator-level users to access com_joomlaupdate and trigger code execution.
Remediation
References
Related Vulnerabilities
IBM RTC Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2016-2865)
WordPress Plugin Product Addons & Fields for WooCommerce Cross-Site Scripting (18.3)
WordPress Plugin Entries For WPForms SQL Injection (1.4.0)
Joomla Improper Input Validation Vulnerability (CVE-2021-26029)