QID 731185
Date Published: 2024-02-26
QID 731185: Joomla Cross-Site Scripting (XSS) Vulnerability (20240204)
Joomla is a free and open-source content management system written in PHP. It uses object oriented programming techniques and is built on a model-view-controller web application framework. It includes features such as page caching, RSS feeds, printable versions of pages, news flashes, blogs, polls, search, and support for language internationalization.
CVE-2024-21725: Joomla versions 4.0.0-4.4.2, 5.0.0-5.0.2 is vulnerable to XSS vulnerability.
Affected Version:
Joomla! CMS versions from 4.0.0 prior to 4.4.3
Joomla! CMS versions from 5.0.0 prior to 5.0.3
Fixed Version:
Upgrade to version 4.4.3 or 5.0.3
QID Detection Logic(Unauthenticated):
QID checks for the Vulnerable version of Joomla.
Successful exploitation of this vulnerability may allow an attacker in inadequate escaping of mail addresses lead to XSS vulnerabilities in various components.
- 20240204 -
developer.joomla.org/security-centre.html
CVEs related to QID 731185
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| 20240204 |
|