An issue was discovered in Joomla! through 3.9.19. A missing token check in the ajax_install endpoint of com_installer causes a CSRF vulnerability.
Source: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-15700
Reference (s):
- https://developer.joomla.org/security-centre/818-20200701-core-csrf-in-com-installer-ajax-install-endpoint.html

