PT-2024-21328 · Unknown · Wrapper Extensions

Jesper Den Boer

·

Published

2024-07-09

·

Updated

2025-04-03

·

CVE-2024-26279

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Wrapper extensions (affected versions not specified)
Description The issue arises from inadequate input validation in the wrapper extensions, leading to Cross-Site Scripting (XSS) vectors. XSS is a type of security vulnerability that allows an attacker to inject malicious scripts into a website, potentially stealing user data or taking control of the user's session. In this case, the lack of proper content filtering in various components of the wrapper extensions makes them susceptible to XSS vulnerabilities.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

XSS

Weakness Enumeration

Related Identifiers

BIT-JOOMLA-2024-26279
CVE-2024-26279

Affected Products

Wrapper Extensions