Description
Joomla! Core is prone to a security bypass vulnerability. Exploiting this issue may allow attackers to perform otherwise restricted actions and subsequently modify the access levels of user groups with higher permissions. Joomla! Core versions ranging from 2.5.0 and up to and including 3.8.7 are vulnerable.
Remediation
Update to Joomla! Core version 3.8.8 or latest
References
Related Vulnerabilities
Oracle HTTP Server CVE-2022-21271 Vulnerability (CVE-2022-21271)
WordPress Plugin Simple Dropbox Upload Arbitrary File Upload (1.8.8)
WordPress Plugin WP Fastest Cache Arbitrary File Deletion (0.8.9.0)
WordPress Plugin DM Albums 'album.php' Remote File Inclusion (1.9.2)
WordPress Plugin Import and export users and customers Cross-Site Scripting (1.14.1.2)