
Cloud Vulnerability DB
A community-led vulnerabilities database
A Cross-Site Request Forgery (CSRF) vulnerability was discovered in Joomla! versions 3.0.0 through 3.9.26, identified as CVE-2021-26034. The vulnerability was reported on May 7, 2021, and fixed on May 25, 2021. The issue stems from a missing token check in data download endpoints specifically affecting the com_banners and com_sysinfo components (Joomla Security).
The vulnerability has been assessed with a CVSS v3.1 score of 6.5 (Medium) and CVSS v2.0 score of 4.3 (Medium). The security issue specifically relates to the absence of proper token validation in the data download endpoints of two Joomla components: com_banners and com_sysinfo (NVD).
The CSRF vulnerability could allow an attacker to trick authenticated users into performing unintended actions on the Joomla installation through data download endpoints. This could potentially lead to unauthorized data access or manipulation of the affected components (CERT-FR).
The vulnerability is classified as having a low severity and impact according to the Joomla Security Team's assessment. It requires user interaction to exploit, as is typical with CSRF vulnerabilities (Joomla Security).
The vulnerability was patched in Joomla! version 3.9.27. Users running affected versions are advised to upgrade to version 3.9.27 or later to mitigate this security issue (Joomla Security).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."