In the Joomla integration, some references to user-account records were not properly sanitized.
CiviCRM versions 5.35.0 and earlier
CiviCRM version 5.35.1 and ESR version 5.33.3
Upgrade to the latest version of CiviCRM
Tim Otten of CiviCRM Core for Reporting and Fixing the issue
Deutsche Gesellschaft für Internationale Zusammenarbeit (GIZ) GmbH for funding the fix
security/core#105