Vulnerabilities > CVE-2020-11889 - Unspecified vulnerability in Joomla Joomla!
Attack vector
NETWORK Attack complexity
LOW Privileges required
NONE Confidentiality impact
NONE Integrity impact
LOW Availability impact
NONE Summary
An issue was discovered in Joomla! before 3.9.17. Incorrect ACL checks in the access level section of com_users allow the unauthorized deletion of usergroups.
Vulnerable Configurations
Nessus
NASL family | CGI abuses |
NASL id | JOOMLA_3917.NASL |
description | According to its self-reported version, the instance of Joomla! running on the remote web server is 2.5.x prior to 3.9.17. It is, therefore, affected by multiple vulnerabilities. - An issue was discovered in Joomla! before 3.9.17. Incorrect ACL checks in the access level section of com_users allow the unauthorized deletion of usergroups. (CVE-2020-11889) - An issue was discovered in Joomla! before 3.9.17. Improper input validations in the usergroup table class could lead to a broken ACL configuration. (CVE-2020-11890) - An issue was discovered in Joomla! before 3.9.17. Incorrect ACL checks in the access level section of com_users allow the unauthorized editing of usergroups. (CVE-2020-11891) Note that Nessus has not tested for these issues but has instead relied only on the application |
last seen | 2020-06-13 |
modified | 2020-04-23 |
plugin id | 135925 |
published | 2020-04-23 |
reporter | This script is Copyright (C) 2020 and is owned by Tenable, Inc. or an Affiliate thereof. |
source | https://www.tenable.com/plugins/nessus/135925 |
title | Joomla 2.5.x < 3.9.17 Multiple Vulnerabilities (5807-joomla-3-9-17) |