Vulnerabilities > CVE-2020-11889 - Incorrect Authorization vulnerability in Joomla Joomla!

047910
CVSS 5.0 - MEDIUM
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
NONE
Integrity impact
PARTIAL
Availability impact
NONE
network
low complexity
joomla
CWE-863
nessus

Summary

An issue was discovered in Joomla! before 3.9.17. Incorrect ACL checks in the access level section of com_users allow the unauthorized deletion of usergroups.

Vulnerable Configurations

Part Description Count
Application
Joomla
263

Common Weakness Enumeration (CWE)

Nessus

NASL familyCGI abuses
NASL idJOOMLA_3917.NASL
descriptionAccording to its self-reported version, the instance of Joomla! running on the remote web server is 2.5.x prior to 3.9.17. It is, therefore, affected by multiple vulnerabilities. - An issue was discovered in Joomla! before 3.9.17. Incorrect ACL checks in the access level section of com_users allow the unauthorized deletion of usergroups. (CVE-2020-11889) - An issue was discovered in Joomla! before 3.9.17. Improper input validations in the usergroup table class could lead to a broken ACL configuration. (CVE-2020-11890) - An issue was discovered in Joomla! before 3.9.17. Incorrect ACL checks in the access level section of com_users allow the unauthorized editing of usergroups. (CVE-2020-11891) Note that Nessus has not tested for these issues but has instead relied only on the application
last seen2020-06-13
modified2020-04-23
plugin id135925
published2020-04-23
reporterThis script is Copyright (C) 2020 and is owned by Tenable, Inc. or an Affiliate thereof.
sourcehttps://www.tenable.com/plugins/nessus/135925
titleJoomla 2.5.x < 3.9.17 Multiple Vulnerabilities (5807-joomla-3-9-17)