Joomla Component jomres 9.11.2 contains a cross-site request forgery vulnerability that allows attackers to modify user account information by tricking authenticated users into visiting malicious pages. Attackers can craft HTML forms targeting the account/index endpoint with hidden fields to change passwords, email addresses, and profile details without user consent.
Metrics
Affected Vendors & Products
References
History
Sat, 23 May 2026 18:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Joomla Component jomres 9.11.2 contains a cross-site request forgery vulnerability that allows attackers to modify user account information by tricking authenticated users into visiting malicious pages. Attackers can craft HTML forms targeting the account/index endpoint with hidden fields to change passwords, email addresses, and profile details without user consent. | |
| Title | Joomla Component jomres 9.11.2 Cross-Site Request Forgery | |
| First Time appeared |
Jomres
Jomres jomres |
|
| Weaknesses | CWE-352 | |
| CPEs | cpe:2.3:a:jomres:jomres:-:*:*:*:*:joomla\!:*:* cpe:2.3:a:jomres:jomres:9.11.2:*:*:*:*:*:*:* |
|
| Vendors & Products |
Jomres
Jomres jomres |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published: 2026-05-23T18:30:54.229Z
Updated: 2026-05-23T18:30:54.229Z
Reserved: 2026-05-23T16:21:11.575Z
Link: CVE-2018-25354
No data.
No data.
No data.