In Joomla! before 3.9.19, missing token checks in com_postinstall lead to CSRF.
The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor.
Link | Tags |
---|---|
https://developer.joomla.org/security-centre/817-20200605-core-csrf-in-com-postinstall | vendor advisory |