Description
A critical vulnerability was reported to the VirtueMart team. This vulnerability could be used by a malicious user to easily gain Super-Admin privileges on your website. The bug was patched and the version 2.6.10 (stable version) and 2.9.9b (in RC state) fixes this issue.
Remediation
Upgrade to the latest version of VirtueMart for Joomla! (this issue was fixed in v2.6.10).
References
Related Vulnerabilities
Jboss EAP Observable Differences in Behavior to Error Inputs Vulnerability (CVE-2021-3642)
WordPress Plugin Integration for Gravity Forms and Pipedrive Cross-Site Scripting (1.0.6)
WordPress Plugin Smart Marketing SMS and Newsletters Forms Security Bypass (2.6.1)
XWiki Improper Control of Generation of Code ('Code Injection') Vulnerability (CVE-2023-46731)
Oracle Application Server CVE-2006-0275 Vulnerability (CVE-2006-0275)