An issue was discovered in Joomla! before 3.9.16. Missing token checks in the image actions of com_templates lead to CSRF.
Source: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-10241
Reference (s):
- https://developer.joomla.org/security-centre/802-20200301-core-csrf-in-com-templates-image-actions

