QID 154094
Date Published: 2021-06-23
QID 154094: Joomla! XSS via logo parameter
An issue was discovered in Joomla! 3.0.0 through 3.9.25. Inadequate escaping allowed XSS attacks using the logo parameter of the default templates on error page
A successful XSS attack can facilitate:
* session cookies being stole and potentially lead to account hijacking
* access to sensitive data to an attacker
* web site defacement
Solution
The vendor has released Joomla 3.9.26 to remediate these vulnerabilities.
Vendor References
CVEs related to QID 154094
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| Download |
|