Description
An issue was discovered in Joomla! 2.5.0 through 3.9.27. Install action in com_installer lack the required hardcoded ACL checks for superusers. A default system is not affected cause the default ACL for com_installer is limited to super users already.
Remediation
References
Related Vulnerabilities
OpenSSL Improper Check for Unusual or Exceptional Conditions Vulnerability (CVE-2025-69420)
SharePoint CVE-2020-17120 Vulnerability (CVE-2020-17120)
WordPress Plugin Estatik Real Estate Arbitrary File Upload (2.2.5)
WordPress Plugin Appointment Hour Booking-WordPress Booking Cross-Site Scripting (1.1.44)