MEDIUM6.1
GHSA-qcv6-h33g-hvrc
Cross-site Scripting (XSS) within joomla/filter class
Quick fix
GHSA-qcv6-h33g-hvrc — joomla/filter: upgrade to the fixed version with the command below.
composer require joomla/filter:^1.4.4Details
An issue was discovered in Joomla! 4.0.0 through 4.1.0. Inadequate content filtering leads to XSS vulnerabilities in various components.
Are you affected?
Enter the version of the package you're using.
Affected packages
References
- https://nvd.nist.gov/vuln/detail/CVE-2022-23800[ADVISORY]
- https://developer.joomla.org/security-centre/877-20220308-core-inadequate-content-filtering-within-the-filter-code.html[WEB]
- https://github.com/FriendsOfPHP/security-advisories/blob/master/joomla/filter/CVE-2022-23800.yaml[WEB]
- https://github.com/joomla-framework/filter[PACKAGE]