VDB
Sign up
MEDIUM

GHSA-fm22-g2q9-j3pw

Joomla! CMS vulnerable to XSS via the input filter

Quick fix

GHSA-fm22-g2q9-j3pw — joomla/filter: upgrade to the fixed version with the command below.

composer require joomla/filter:^4.0.1

Details

Improper handling of input could lead to a cross-site scripting (XSS) vector in the checkAttribute method of the input filter framework class.

Are you affected?

Enter the version of the package you're using.

Affected packages

Packagist/joomla/filter
Introduced in: 4.0.0Fixed in: 4.0.1
Fixcomposer require joomla/filter:^4.0.1
Packagist/joomla/filter
Introduced in: 3.0.0Fixed in: 3.0.5
Fixcomposer require joomla/filter:^3.0.5
Packagist/joomla/filter
Introduced in: 0Fixed in: 2.0.6
Fixcomposer require joomla/filter:^2.0.6

References