An issue was discovered in Joomla! through 3.9.19. Internal read-only fields in the User table class could be modified by users.
Source: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-15697
Reference (s):
- https://developer.joomla.org/security-centre/821-20200704-core-variable-tampering-via-user-table-class.html

