Joomla! 3.4.4 through 3.6.3 allows attackers to reset username, password, and user group assignments and possibly perform other user account modifications via unspecified vectors.
Weaknesses in this category are related to the management of credentials.
Link | Tags |
---|---|
http://www.securityfocus.com/bid/93969 | vdb entry third party advisory |
https://developer.joomla.org/security-centre/661-20161003-core-account-modifications.html | patch vendor advisory |