Description
The CMS installer in Joomla! before 3.7.4 does not verify a user's ownership of a webspace, which allows remote authenticated users to gain control of the target application by leveraging Certificate Transparency logs.
Remediation
References
Related Vulnerabilities
Moodle Resource Management Errors Vulnerability (CVE-2015-0217)
Joomla! Core 1.7.0 Information Disclosure (1.7.0)
Internet Information Services Other Vulnerability (CVE-2003-0226)
Oracle Database Server CVE-2012-1708 Vulnerability (CVE-2012-1708)
WordPress Plugin Download Monitor Unspecified Vulnerability (1.9.6)