PT-2020-7120 · Joomla · Joomla!

Aung Khant

·

Published

2020-01-22

·

Updated

2020-01-24

·

CVE-2011-3595

CVSS v2.0

3.5

Low

VectorAV:N/AC:M/Au:S/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions Joomla! versions prior to 1.7.0
Description Multiple Cross-site Scripting (XSS) vulnerabilities exist in the index.php file, specifically in the search word, extension, asset, and author parameters. This issue allows for potential exploitation through these parameters in the "/index.php" endpoint.
Recommendations For versions prior to 1.7.0, update to a version that includes the fix for this issue to prevent exploitation. As a temporary workaround, consider restricting access to the vulnerable parameters search word, extension, asset, and author in the index.php file until a patch is available.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2011-3595

Affected Products

Joomla!