580
VMScore

CVE-2020-10239

Published: 16/03/2020 Updated: 21/07/2021
CVSS v2 Base Score: 6.5 | Impact Score: 6.4 | Exploitability Score: 8
CVSS v3 Base Score: 8.8 | Impact Score: 5.9 | Exploitability Score: 2.8
VMScore: 580
Vector: AV:N/AC:L/Au:S/C:P/I:P/A:P

Vulnerability Summary

An issue exists in Joomla! prior to 3.9.16. Incorrect Access Control in the SQL fieldtype of com_fields allows access for non-superadmin users.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

joomla joomla\\!

Github Repositories

CVE-2020-10238: Incorrect Access Control in com_templates PoC

Made by HK CVE-2020-10238: Incorrect Access Control in com_templates- RCE CVE-2020-10239: Incorrect Access Control in com_fields SQL field- RCE Link developerjoomlaorg/security-centre/804-20200303-core-incorrect-access-control-in-com-templateshtml developerjoomlaorg/security-centre/806-20200305-core-incorrect-access-control-in-com-fields-sql-fieldhtml My b

CVE-2020-10238: Incorrect Access Control in com_templates PoC

Made by HK CVE-2020-10238: Incorrect Access Control in com_templates- RCE CVE-2020-10239: Incorrect Access Control in com_fields SQL field- RCE Link developerjoomlaorg/security-centre/804-20200303-core-incorrect-access-control-in-com-templateshtml developerjoomlaorg/security-centre/806-20200305-core-incorrect-access-control-in-com-fields-sql-fieldhtml My b

CVE-2020-10239: Incorrect Access Control in com_fields SQL field-RCE- PoC

Made by HK CVE-2020-10239: Incorrect Access Control in com_fields SQL field - RCE PoC Affected version: Joomla core from 370 to 3915 User requirement: Manager account(Lowest-level in back-end) Gain access: Change you from Manager to Superadmin, then trigger RCE Remote Code Execution (RCE) in Joomla Run cve202010239py with your credentials and access link rce: