Description
Joomla Component jomres 9.11.2 contains a cross-site request forgery vulnerability that allows attackers to modify user account information by tricking authenticated users into visiting malicious pages. Attackers can craft HTML forms targeting the account/index endpoint with hidden fields to change passwords, email addresses, and profile details without user consent.
Problem types
Cross-Site Request Forgery (CSRF)
Product status
Credits
L0RD
References
www.exploit-db.com/exploits/44901 (ExploitDB-44901)
www.jomres.net/ (Official Product Homepage)
extensions.joomla.org/extension/jomres/ (Product Reference)
www.vulncheck.com/...onent-jomres-cross-site-request-forgery (VulnCheck Advisory: Joomla Component jomres 9.11.2 Cross-Site Request Forgery)