CVE-2020-13760
HIGHJoomla! < 3.9.19 - Cross-Site Request Forgery in com_postinstall
Title source: llmDescription
In Joomla! before 3.9.19, missing token checks in com_postinstall lead to CSRF.
References (1)
Core 1
Core References
Vendor Advisory x_refsource_misc
https://developer.joomla.org/security-centre/817-20200605-core-csrf-in-com-postinstall
Scores
CVSS v3
8.8
EPSS
0.0001
EPSS Percentile
0.8%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Details
CWE
CWE-352
Status
published
Products (2)
joomla/joomla\!
3.7.0 (11 CPE variants)
joomla/joomla\!
3.7.1 - 3.9.19
Published
Jun 02, 2020
Tracked Since
Feb 18, 2026