MEDIUM6.1
GHSA-v84j-vh7x-g7j6
Joomla! XSS in Default Templates
Quick fix
GHSA-v84j-vh7x-g7j6 — joomla/joomla-cms: upgrade to the fixed version with the command below.
composer require joomla/joomla-cms:^3.9.12Details
In Joomla! 3.x before 3.9.12, inadequate escaping allowed XSS attacks using the logo parameter of the default templates.
Are you affected?
Enter the version of the package you're using.
Affected packages
Packagist/joomla/joomla-cms
Introduced in:
3.0.0Fixed in: 3.9.12Fix
composer require joomla/joomla-cms:^3.9.12