Description
An issue was discovered in Joomla! before 3.9.7. The update server URL of com_joomlaupdate can be manipulated by non Super-Admin users.
Remediation
References
Related Vulnerabilities
Vanilla Forums Deserialization of Untrusted Data Vulnerability (CVE-2018-19499)
WordPress Plugin EWWW Image Optimizer Cross-Site Request Forgery (5.8.1)
Squid Out-of-bounds Read Vulnerability (CVE-2021-28116)
WordPress Plugin PWG Random Cross-Site Request Forgery (1.11)
WordPress Plugin Jigoshop Unspecified Vulnerability (1.10.5)