QID 154116

Date Published: 2022-05-27

QID 154116: Joomla! Core Multiple Vulnerabilities (CVE-2022-23799,CVE-2022-23800,CVE-2022-23801)

Joomla! is a free and open-source content management system for publishing web content on websites.

Affected versions of Joomla Core have multiple vulnerabilities:
CVE-2022-23799 : Under specific circumstances, JInput pollutes method-specific input bags with $_REQUEST data.
CVE-2022-23800 : Inadequate content filtering leads to XSS vulnerabilities in various components.
CVE-2022-23801 : Possible XSS attack vector through SVG embedding in com_media.

Affected Versions:
Joomla! CMS versions 4.0.0 - 4.1.0

QID Detection Logic:(Unauthenticated)
This QID checks for vulnerable version of Joomla installed on the target.

Successful exploitation of these vulnerabilities could allow an unauthenticated attacker to compromise Joomla Server.

  • CVSS V3 rated as Critical - 9.8 severity.
  • CVSS V2 rated as High - 6.8 severity.
  • Solution

    CVEs related to QID 154116

    Software Advisories
    Advisory ID Software Component Link
    20220307 URL Logo developer.joomla.org/security-centre/876-20220307-core-variable-tampering-on-jinput-request-data.html
    20220308 URL Logo developer.joomla.org/security-centre/877-20220308-core-inadequate-content-filtering-within-the-filter-code.html
    20220309 URL Logo developer.joomla.org/security-centre/878-20220309-core-xss-attack-vector-through-svg.html