Joomla!
cpe:2.3:a:joomla:joomla!:*:*:*:*:*:*:*
- >= 3.0.0, <= 5.4.3
- >= 6.0.0, <= 6.0.3
An access control vulnerability has been identified in the Joomla! CMS ajax component, specifically in versions 3.0.0 prior to 5.4.3 and 6.0.0 prior to 6.0.3. The issue arises because the ajax component was not subjected to the standard logged-in-user verification in the administrative area, potentially leading to unexpected behavior for third-party developers.
This vulnerability could allow unauthorized access to the ajax component in the administrative area, bypassing the default user authentication checks.
Users can upgrade to Joomla! CMS versions 5.4.4 or 6.0.4 to address this vulnerability.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.