MEDIUM4.8
GHSA-g3m5-vvj7-xrwv
Joomla! XSS Vulnerability
Quick fix
GHSA-g3m5-vvj7-xrwv — joomla/joomla-cms: upgrade to the fixed version with the command below.
composer require joomla/joomla-cms:^3.8.8Details
An issue was discovered in Joomla! Core starting in 3.0.0 and prior to 3.8.8. Inadequate input filtering leads to a multiple XSS vulnerabilities. Additionally, the default filtering settings could potentially allow users of the default Administrator user group to perform a XSS attack.
Are you affected?
Enter the version of the package you're using.
Affected packages
Packagist/joomla/joomla-cms
Introduced in:
3.0.0Fixed in: 3.8.8Fix
composer require joomla/joomla-cms:^3.8.8References
- https://nvd.nist.gov/vuln/detail/CVE-2018-11326[ADVISORY]
- https://developer.joomla.org/security-centre/733-20180505-core-xss-vulnerabilities-additional-hadering.html[WEB]
- https://github.com/joomla/joomla-cms[PACKAGE]
- https://web.archive.org/web/20210124173032/http://www.securityfocus.com/bid/104270[WEB]
- https://web.archive.org/web/20211129145422/http://www.securitytracker.com/id/1040966[WEB]