PT-2019-13759 · Open Source Matters · Joomla!

Benjamin Trenkle

·

Published

2019-08-05

·

Updated

2020-08-24

·

CVE-2019-14654

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Joomla! versions 3.9.7 through 3.9.8
Description The issue allows users authorized to create custom fields to manipulate filtering options and inject unvalidated options, potentially leading to remote code execution due to inadequate filtering in subform fields.
Recommendations For versions 3.9.7 and 3.9.8, update to version 3.9.9 to resolve the issue.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2019-14654

Affected Products

Joomla!