PT-2022-16268 · Joomla · Joomla!

Hoàng Nguyễn

·

Published

2022-03-30

·

Updated

2025-04-03

·

CVE-2022-23796

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Joomla! versions 3.7.0 through 3.10.6
Description The issue is related to a lack of input validation, which could allow an XSS attack using com fields.
Recommendations For Joomla! versions 3.7.0 through 3.10.6, update to a version that includes the fix for this issue. As a temporary workaround, consider restricting access to com fields to minimize the risk of exploitation.

Fix

XSS

Weakness Enumeration

Related Identifiers

BIT-JOOMLA-2022-23796
CVE-2022-23796

Affected Products

Joomla!