QID 730631

Date Published:

QID 730631: Joomla Multiple Security Vulnerabilities (20221001, 20221002)

Joomla is a free and open-source content management system written in PHP. It uses object oriented programming techniques and is built on a model-view-controller web application framework. It includes features such as page caching, RSS feeds, printable versions of pages, news flashes, blogs, polls, search, and support for language internationalization.

CVE-2022-27913: Inadequate filtering of potentially malicious user input leads to reflected XSS vulnerabilities in various components.
CVE-2022-27912: Joomla 4 sites with publicly enabled debug mode exposed data of previous requests.

Affected Version:
Joomla! CMS versions from 4.0.0 to 4.2.3

Fixed Version:
Upgrade to version 4.2.4

QID Detection Logic(Unauthenticated):
QID checks for the Vulnerable version of Joomla.

Successful exploitation of this vulnerability may allow an attacker to either expose or steal sensitive data of the targeted user.

  • CVSS V3 rated as High - 6.1 severity.
  • CVSS V2 rated as High - 6.4 severity.
  • Solution
    The vendor has released a patch in Joomla to remediate this vulnerability.
    Vendor References

    CVEs related to QID 730631

    Software Advisories
    Advisory ID Software Component Link
    20221001 and 20221002 URL Logo developer.joomla.org/security-centre.html