#VU266 ACL security bypass in com_content component in Joomla!
Published: August 8, 2016 / Updated: August 15, 2016
Joomla!
Joomla!
Description
The vulnerability allows a remote authenticated user to access otherwise restricted content.
The vulnerability exists in com_content component when validating ACLs for different users. A remote authenticated user can read data, which should be available only to users with edit_own level privileges.
Successful exploitation of this vulnerability may allow an attacker to obtain potentially sensitive information.