CVE-2010-1435

Joomla! Core is prone to a security bypass vulnerability. Exploiting this issue may allow attackers to perform otherwise restricted actions and subsequently retrieve password reset tokens from the database through an already existing SQL injection vector. Joomla! Core versions 1.5.x ranging from 1.5.0 and up to and including 1.5.15 are vulnerable.
Configurations

Configuration 1 (hide)

cpe:2.3:a:joomla:joomla\!:*:*:*:*:*:*:*:*

History

25 Jun 2021, 15:14

Type Values Removed Values Added
References (MISC) https://www.acunetix.com/vulnerabilities/web/joomla-core-1-5-x-security-bypass-1-5-0-1-5-15/ - (MISC) https://www.acunetix.com/vulnerabilities/web/joomla-core-1-5-x-security-bypass-1-5-0-1-5-15/ - Third Party Advisory
References (MISC) https://developer.joomla.org/security-centre/308-20100423-core-password-reset-tokens.html - (MISC) https://developer.joomla.org/security-centre/308-20100423-core-password-reset-tokens.html - Vendor Advisory
CPE cpe:2.3:a:joomla:joomla\!:*:*:*:*:*:*:*:*
CVSS v2 : unknown
v3 : unknown
v2 : 7.5
v3 : 9.8
CWE CWE-863

21 Jun 2021, 23:15

Type Values Removed Values Added
New CVE

Information

Published : 2021-06-21 23:15

Updated : 2023-12-10 13:55


NVD link : CVE-2010-1435

Mitre link : CVE-2010-1435

CVE.ORG link : CVE-2010-1435


JSON object : View

Products Affected

joomla

  • joomla\!
CWE
CWE-863

Incorrect Authorization