GHSA-w384-fv8f-hx76MediumCVSS 4.3
Joomla Component jomres 9.11.2 contains a cross-site request forgery vulnerability that allows...
🔗 CVE IDs covered (1)
📋 Description
Joomla Component jomres 9.11.2 contains a cross-site request forgery vulnerability that allows attackers to modify user account information by tricking authenticated users into visiting malicious pages. Attackers can craft HTML forms targeting the account/index endpoint with hidden fields to change passwords, email addresses, and profile details without user consent.