QID 730636

Date Published: 2022-11-09

QID 730636: Joomla Multiple Security Vulnerabilities (20220307, 20220308 and 20220309)

Joomla is a free and open-source content management system written in PHP. It uses object oriented programming techniques and is built on a model-view-controller web application framework. It includes features such as page caching, RSS feeds, printable versions of pages, news flashes, blogs, polls, search, and support for language internationalization.

CVE-2022-23799: Under specific circumstances, JInput pollutes method-specific input bags with $_REQUEST data.
CVE-2022-23800: Inadequate content filtering leads to XSS vulnerabilities in various components.
CVE-2022-23801: Possible XSS attack vector through SVG embedding in com_media.

Affected Version:
Joomla! CMS versions from 4.0.0 to 4.1.0

Fixed Version:
Upgrade to version 4.1.1

QID Detection Logic(Unauthenticated):
QID checks for the Vulnerable version of Joomla.

Successful exploitation of these vulnerabilities could allow an unauthenticated attacker to compromise Joomla Server.

  • CVSS V3 rated as Critical - 9.8 severity.
  • CVSS V2 rated as High - 6.8 severity.
  • Solution
    The vendor has released a patch in Joomla to remediate this vulnerability.
    Vendor References

    CVEs related to QID 730636

    Software Advisories
    Advisory ID Software Component Link
    20220307, 20220308 and 20220309 URL Logo developer.joomla.org/security-centre.html