The register method in the UsersModelRegistration class in controllers/user.php in the Users component in Joomla! before 3.6.4 allows remote attackers to gain privileges by leveraging incorrect use of unfiltered data when registering on a site.
{ "versions": [ { "introduced": "0" }, { "last_affected": "3.6.3" } ] }
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2016-8869.json"