The MFA management features did not properly terminate existing user sessions when a user’s MFA methods have been modified.
CVE-2023-21722
This vulnerability affects the following application versions:
- Joomla 4.2.0
- Joomla 4.2.1
- Joomla 4.2.2
- Joomla 4.2.3
- Joomla 4.2.4
- Joomla 4.2.5
- Joomla 4.2.6
- Joomla 4.2.7
- Joomla 4.2.8
- Joomla 4.2.9
- Joomla 4.3.0
- Joomla 4.3.1
- Joomla 4.3.2
- Joomla 4.3.3
- Joomla 4.3.4
- Joomla 4.4.0
- Joomla 4.4.1
- Joomla 4.4.2
- Joomla 5.0.0
- Joomla 5.0.1
- Joomla 5.0.2