QID 995450
Date Published: 2023-10-03
QID 995450: PHP (Composer) Security Update for joomla/application (GHSA-h22q-g2c7-2jwj)
CRLF injection vulnerability in Joomla! before 1.0.13 (aka Sunglow) allows remote attackers to inject arbitrary HTTP headers and probably conduct HTTP response splitting attacks via CRLF sequences in the url parameter. NOTE: this can be leveraged for cross-site scripting (XSS) attacks. NOTE: some of these details are obtained from third party information.
Successful exploitation of this vulnerability could lead to a security breach or could affect integrity, availability, and confidentiality.
Solution
Refer to Github security advisory GHSA-h22q-g2c7-2jwj for updates and patch information.
Vendor References
- GHSA-h22q-g2c7-2jwj -
github.com/advisories/GHSA-h22q-g2c7-2jwj
CVEs related to QID 995450
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-h22q-g2c7-2jwj | joomla/application |
|