QID 730636
Date Published: 2022-11-09
QID 730636: Joomla Multiple Security Vulnerabilities (20220307, 20220308 and 20220309)
Joomla is a free and open-source content management system written in PHP. It uses object oriented programming techniques and is built on a model-view-controller web application framework. It includes features such as page caching, RSS feeds, printable versions of pages, news flashes, blogs, polls, search, and support for language internationalization.
CVE-2022-23799: Under specific circumstances, JInput pollutes method-specific input bags with $_REQUEST data.
CVE-2022-23800: Inadequate content filtering leads to XSS vulnerabilities in various components.
CVE-2022-23801: Possible XSS attack vector through SVG embedding in com_media.
Affected Version:
Joomla! CMS versions from 4.0.0 to 4.1.0
Fixed Version:
Upgrade to version 4.1.1
QID Detection Logic(Unauthenticated):
QID checks for the Vulnerable version of Joomla.
Successful exploitation of these vulnerabilities could allow an unauthenticated attacker to compromise Joomla Server.
- 20220307, 20220308 and 20220309 -
developer.joomla.org/security-centre.html
CVEs related to QID 730636
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| 20220307, 20220308 and 20220309 |
|