vendor:
Joomla CMS
by:
Praveen Sutar
4.8
CVSS
MEDIUM
Stored XSS
79
CWE
Product Name: Joomla CMS
Affected Version From: 2.5.2000
Affected Version To: 3.9.2001
Patch Exists: YES
Related CWE: CVE-2019-6263
CPE: a:joomla:cms:3.9.1
Platforms Tested: Joomla 3.9.1
2019
Joomla Global Configuration Text Filter settings Stored XSS Vulnerability
Joomla Core - Stored XSS issue in the Global Configuration textfilter settings. Joomla fails to perform adequate checks at the Global Configuration Text Filter settings which allows a stored XSS.
Mitigation:
Upgrade to the latest version of Joomla