Joomla · Acymailing Enterprise · CVE-2023-39971
**Name of the Vulnerable Software and Affected Versions**
AcyMailing Enterprise component for Joomla versions 6.7.0 through 8.6.3
**Description**
The issue is related to improper neutralization of input during web page generation, allowing Cross-Site Scripting (XSS). This enables potential attackers to inject malicious scripts into web pages.
**Recommendations**
For versions 6.7.0 through 8.6.3, update to a version that includes a fix for this issue. As a temporary workaround, consider restricting user input to minimize the risk of exploitation.