PT-2024-21327 · Unknown · Custom Fields

Jesper Den Boer

·

Published

2024-07-09

·

Updated

2025-04-03

·

CVE-2024-26278

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Custom Fields component (affected versions not specified)
Description The issue is related to the Custom Fields component not correctly filtering inputs, which leads to a cross-site scripting (XSS) vector. This means an attacker could potentially inject malicious scripts into the component, affecting the security of the system.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BIT-JOOMLA-2024-26278
CVE-2024-26278

Affected Products

Custom Fields