PT-2018-10487 · Joomla · Joomla! Core

David Jardin

·

Published

2018-05-22

·

Updated

2018-06-22

·

CVE-2018-11328

CVSS v3.1

4.7

Medium

VectorAV:N/AC:H/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Joomla! Core versions prior to 3.8.8
Description A lack of escaping the user-info component of the URI could result in an XSS issue under specific circumstances, such as when a redirect is issued with a URI containing a username and password, and the Location: header cannot be used.
Recommendations For versions prior to 3.8.8, update to version 3.8.8 or later to resolve the issue.

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2018-11328

Affected Products

Joomla! Core