CVE-2010-1435

CRITICAL

Joomla! Core <1.5.16 - Privilege Escalation

Title source: llm
STIX 2.1

Description

Joomla! Core is prone to a security bypass vulnerability. Exploiting this issue may allow attackers to perform otherwise restricted actions and subsequently retrieve password reset tokens from the database through an already existing SQL injection vector. Joomla! Core versions 1.5.x ranging from 1.5.0 and up to and including 1.5.15 are vulnerable.

Scores

CVSS v3 9.8
EPSS 0.0001
EPSS Percentile 2.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-863
Status published
Products (1)
joomla/joomla\! 1.5.0 - 1.5.15
Published Jun 21, 2021
Tracked Since Feb 18, 2026