VDB
Sign up
MEDIUM6.1

GHSA-qcv6-h33g-hvrc

Cross-site Scripting (XSS) within joomla/filter class

Quick fix

GHSA-qcv6-h33g-hvrc — joomla/filter: upgrade to the fixed version with the command below.

composer require joomla/filter:^1.4.4

Details

An issue was discovered in Joomla! 4.0.0 through 4.1.0. Inadequate content filtering leads to XSS vulnerabilities in various components.

Are you affected?

Enter the version of the package you're using.

Affected packages

Packagist/joomla/filter
Introduced in: 0Fixed in: 1.4.4
Fixcomposer require joomla/filter:^1.4.4
Packagist/joomla/filter
Introduced in: 2.0.0Fixed in: 2.0.1
Fixcomposer require joomla/filter:^2.0.1

References