PT-2020-13664 · Joomla · Joomla!

Brian Teeman

·

Published

2020-06-02

·

Updated

2025-04-03

·

CVE-2020-13763

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions Joomla! versions prior to 3.9.19
Description The default settings of the global textfilter configuration in Joomla! do not block HTML inputs for Guest users. This issue may allow unauthorized users to inject malicious HTML code.
Recommendations For versions prior to 3.9.19, update to version 3.9.19 or later to resolve the issue. As a temporary workaround, consider modifying the global textfilter configuration to block HTML inputs for Guest users. Restrict access to sensitive areas of the application to minimize the risk of exploitation.

Fix

Improper Preservation of Permissions

Weakness Enumeration

Related Identifiers

BIT-JOOMLA-2020-13763
CVE-2020-13763

Affected Products

Joomla!