Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-vcq7-x4wr-w2mj

Опубликовано: 14 мая 2022
Источник: github
Github: Прошло ревью
CVSS4: 5.3

Описание

Joomla! vulnerable to Cross-site Scripting

Multiple cross-site scripting (XSS) vulnerabilities in Joomla! before 1.6.4 allow remote attackers to inject arbitrary web script or HTML via (1) the query string to the com_contact component, as demonstrated by the Itemid parameter to index.php; (2) the query string to the com_content component, as demonstrated by the filter_order parameter to index.php; (3) the query string to the com_newsfeeds component, as demonstrated by an arbitrary parameter to index.php; or (4) the option parameter in a reset.request action to index.php; and, when Internet Explorer or Konqueror is used, (5) allow remote attackers to inject arbitrary web script or HTML via the searchword parameter in a search action to index.php in the com_search component.

Пакеты

Наименование

joomla/joomla-cms

composer
Затронутые версииВерсия исправления

< 1.6.4

1.6.4

EPSS

Процентиль: 7%
0.00027
Низкий

5.3 Medium

CVSS4

Дефекты

CWE-79

Связанные уязвимости

nvd
больше 14 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in Joomla! before 1.6.4 allow remote attackers to inject arbitrary web script or HTML via (1) the query string to the com_contact component, as demonstrated by the Itemid parameter to index.php; (2) the query string to the com_content component, as demonstrated by the filter_order parameter to index.php; (3) the query string to the com_newsfeeds component, as demonstrated by an arbitrary parameter to index.php; or (4) the option parameter in a reset.request action to index.php; and, when Internet Explorer or Konqueror is used, (5) allow remote attackers to inject arbitrary web script or HTML via the searchword parameter in a search action to index.php in the com_search component.

EPSS

Процентиль: 7%
0.00027
Низкий

5.3 Medium

CVSS4

Дефекты

CWE-79