An issue was discovered in Joomla! before 3.9.13. A missing token check in com_template causes a CSRF vulnerability.
The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor.
Link | Tags |
---|---|
https://developer.joomla.org/security-centre/794-20191001-core-csrf-in-com-template-overrides-view.html | vendor advisory |