Description
The CMS installer in Joomla! before 3.7.4 does not verify a user's ownership of a webspace, which allows remote authenticated users to gain control of the target application by leveraging Certificate Transparency logs.
Remediation
References
Related Vulnerabilities
XWiki Files or Directories Accessible to External Parties Vulnerability (CVE-2022-23621)
IBM RTC Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2017-1559)
CubeCart Improper Input Validation Vulnerability (CVE-2013-1465)
Oracle Database Server CVE-2024-21184 Vulnerability (CVE-2024-21184)