In Joomla! before 3.8.2, a bug allowed third parties to bypass a user's 2-factor authentication method.
When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.
Link | Tags |
---|---|
http://www.securityfocus.com/bid/101701 | third party advisory vdb entry |
https://developer.joomla.org/security-centre/713-20171102-core-2-factor-authentication-bypass | patch vendor advisory |
http://www.securitytracker.com/id/1039757 | third party advisory vdb entry |