Description
An issue was discovered in Joomla! 2.5.0 through 3.9.27. Install action in com_installer lack the required hardcoded ACL checks for superusers. A default system is not affected cause the default ACL for com_installer is limited to super users already.
Remediation
References
Related Vulnerabilities
PHP CVE-2007-5898 Vulnerability (CVE-2007-5898)
WebLogic Observable Discrepancy Vulnerability (CVE-2019-3739)
WordPress Plugin PHP Event Calendar for WordPress Arbitrary File Upload (1.6)
TYPO3 7PK - Security Features Vulnerability (CVE-2016-5091)
Internet Information Services Other Vulnerability (CVE-2001-1186)