QID 154116
Date Published: 2022-05-27
QID 154116: Joomla! Core Multiple Vulnerabilities (CVE-2022-23799,CVE-2022-23800,CVE-2022-23801)
Joomla! is a free and open-source content management system for publishing web content on websites.
Affected versions of Joomla Core have multiple vulnerabilities:
CVE-2022-23799 : Under specific circumstances, JInput pollutes method-specific input bags with $_REQUEST data.
CVE-2022-23800 : Inadequate content filtering leads to XSS vulnerabilities in various components.
CVE-2022-23801 : Possible XSS attack vector through SVG embedding in com_media.
Affected Versions:
Joomla! CMS versions 4.0.0 - 4.1.0
QID Detection Logic:(Unauthenticated)
This QID checks for vulnerable version of Joomla installed on the target.
Successful exploitation of these vulnerabilities could allow an unauthenticated attacker to compromise Joomla Server.
Solution
Customers are advised to install latest Joomla version.
For more information visit:
Joomla security advisory [20220307].
Joomla security advisory [20220308].
Joomla security advisory [20220309].
For more information visit:
Joomla security advisory [20220307].
Joomla security advisory [20220308].
Joomla security advisory [20220309].
Vendor References
- 20220307 -
developer.joomla.org/security-centre/876-20220307-core-variable-tampering-on-jinput-request-data.html - 20220308 -
developer.joomla.org/security-centre/877-20220308-core-inadequate-content-filtering-within-the-filter-code.html - 20220309 -
developer.joomla.org/security-centre/878-20220309-core-xss-attack-vector-through-svg.html
CVEs related to QID 154116
Software Advisories