PT-2007-4528 · Open Source Matters · Joomla!

Published

2007-06-18

·

Updated

2017-07-29

·

CVE-2007-3249

CVSS v2.0

4.3

Medium

VectorAV:N/AC:M/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions: Joomla! mod letterman module versions prior to 1.2.5
Description: A cross-site scripting (XSS) issue exists, allowing remote attackers to inject arbitrary web script or HTML via the Itemid parameter in the mod lettermansubscribe.php file.
Recommendations: For versions prior to 1.2.5, update to version 1.2.5 or later to resolve the issue. As a temporary workaround, consider restricting access to the mod lettermansubscribe.php file until a patch is applied. Avoid using the Itemid parameter in the affected module until the issue is resolved.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2007-3249

Affected Products

Joomla!