Home
MEDIUM: 6.4 CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:L/SC:H/SI:H/SA:HDefault status
unaffected
4.1.0-5.4.5
affected
6.0.0-6.1.0
affected
Description
An improper access check allowed low privileged users to edit the task types of existing scheduler tasks.
Problem types
CWE-284 Improper Access Control
Product status
4.1.0-5.4.5
6.0.0-6.1.0
Credits
Federico Brasili, https://www.linkedin.com/in/federico-brasili-00b4b7332/
References
developer.joomla.org/...access-control-in-com-scheduler.html