Description
An issue was discovered in Joomla! 2.5.0 through 3.10.6 & 4.0.0 through 4.1.0. A user row was not bound to a specific authentication mechanism which could under very special circumstances allow an account takeover.
Remediation
References
Related Vulnerabilities
Roundcube Cross-site Scripting (XSS) Vulnerability (CVE-2015-8864)
WordPress Plugin WP Editor.md Cross-Site Scripting (10.0.1)
WordPress Plugin Relevanssi-A Better Search SQL Injection (3.2)
WordPress Plugin Cherry Services List Information Disclosure (1.4.1)
Grafana Server-Side Request Forgery (SSRF) Vulnerability (CVE-2020-13379)