CVE-2026-48948

Vulnérabilités

CVE-2026-48948

Incorrect Access Control in com_contact vcf download

LOW Joomla CMS Source officielle

An improper access check allows user to download vcard exports of com_contact contacts that are inaccessible.

Source officielle Description du Joomla Security Centre (Joomla).

— Faible
SourceSévérité d'origineCVSS
Joomla Security CentreLow —
CERT-FR (ANSSI)— —
Produit
Joomla CMS
Corrigée dans
5.4.7, 6.1.2
Publiée
07/07/2026
Modifiée
08/07/2026
  • 3.0.0 – 5.4.6
  • 6.0.0 – 6.1.1
  • Joomla Security Centre Source officielle Avis vu
  • CERT-FR (ANSSI) Avis vu

Ces informations proviennent des sources ci-dessus ; CVE Oyer n'y ajoute aucune interprétation.

  1. Source ajoutée : certfr26/09/2026 09:28 UTC
  2. Détectée via joomla26/09/2026 09:26 UTC