Vulnerability Description
An issue was discovered in Joomla! 4.0.0. The media manager does not correctly check the user's permissions before executing a file deletion command.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Joomla | Joomla\! | 4.0.0 |
Related Weaknesses (CWE)
References
- https://developer.joomla.org/security-centre/861-20210801-core-insufficient-acceVendor Advisory
- https://developer.joomla.org/security-centre/861-20210801-core-insufficient-acceVendor Advisory
FAQ
What is CVE-2021-26040?
CVE-2021-26040 is a vulnerability with a CVSS score of 9.1 (CRITICAL). An issue was discovered in Joomla! 4.0.0. The media manager does not correctly check the user's permissions before executing a file deletion command.
How severe is CVE-2021-26040?
CVE-2021-26040 has been rated CRITICAL with a CVSS base score of 9.1/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2021-26040?
Check the references section above for vendor advisories and patch information. Affected products include: Joomla Joomla\!.