Lack of input validation while handling ACL rulesets can cause write ACL violations.
Joomla! CMS versions 1.7.0 - 3.9.22
Upgrade to version 3.9.23
The JSST at the Joomla! Security Centre.
A missing token check in the emailexport feature of com_privacy causes a CSRF vulnerability.
Joomla! CMS versions 3.9.0 - 3.9.22
Upgrade to version 3.9.23
The JSST at the Joomla! Security Centre.
Improper handling of the username leads to a user enumeration attack vector in the backend login page.
Joomla! CMS versions 3.9.0 - 3.9.22
Upgrade to version 3.9.23
The JSST at the Joomla! Security Centre.
Improper filter blacklist configuration leads to a SQL injection vulnerability in the backend user list.
Joomla! CMS versions 3.0.0 - 3.9.22
Upgrade to version 3.9.23
The JSST at the Joomla! Security Centre.
The folder parameter of mod_random_image lacked input validation, leading to a path traversal vulnerability.
Joomla! CMS versions 2.5.0 - 3.9.22
Upgrade to version 3.9.23
The JSST at the Joomla! Security Centre.