Joomla's access-level API endpoints inherited permissive default permission checks, so an authenticated user with only create or edit rights on com_users could add or modify access levels. The fix requires core.admin instead. This vulnerability affects the following application versions: Joomla 4.1.0 Joomla 4.1.1 Joomla 4.1.2 Joomla 4.1.3 Joomla... Weiterlesen: Incorrect Access Control in Joomla com_users Access Level API
Intelligence View
⚡ tsecurity.de Intelligence
Incorrect Access Control in Joomla com_users Access Level API
Joomla's access-level API endpoints inherited permissive default permission checks, so an authenticated user with only create or edit rights on com_users could…