QID 730049

Date Published: 2021-04-19

QID 730049: Joomla Multiple Security Vulnerability(20210402, 20210401)

Joomla is a free and open-source content management system written in PHP. It uses object oriented programming techniques and is built on a model-view-controller web application framework. It includes features such as page caching, RSS feeds, printable versions of pages, news flashes, blogs, polls, search, and support for language internationalization.

Affected Version:
Joomla! CMS versions 3.0.0 - 3.9.25

Fixed Version:
Upgrade to version 3.9.26

QID Detection Logic(Unauthenticated):
QID checks for the Vulnerable version of Joomla.

Successful exploitation could affects on integrity, confidentiality, availability.

  • CVSS V3 rated as High - 7.3 severity.
  • CVSS V2 rated as Low - 0 severity.
  • Solution
    The vendor has released a patch in Joomla to remediate this vulnerability.

    CVEs related to QID 730049

    Software Advisories
    Advisory ID Software Component Link
    20210401 URL Logo developer.joomla.org/security-centre/850-20210401-core-escape-xss-in-logo-parameter-error-pages.html
    20210402 URL Logo developer.joomla.org/security-centre/851-20210402-core-inadequate-filters-on-module-layout-settings.html