vendor:
com_alfcontact
by:
Not provided
5.5
CVSS
MEDIUM
Cross-Site Scripting (XSS)
79
CWE
Product Name: com_alfcontact
Affected Version From: 1.9.2000
Affected Version To: 1.9.2003
Patch Exists: YES
Related CWE: Not provided
CPE: a:joomla:com_alfcontact
Platforms Tested: Not provided
Not provided
Joomla! ‘com_alfcontact’ Extension Multiple Cross-Site Scripting Vulnerabilities
The Joomla! 'com_alfcontact' extension is prone to multiple cross-site scripting vulnerabilities because it fails to properly sanitize user-supplied input. An attacker could leverage these issues to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This could allow the attacker to steal cookie-based authentication credentials and launch other attacks.
Mitigation:
Update to Joomla! 'com_alfcontact' extension version 1.9.3 or later. Sanitize and validate user-supplied input before using it in web applications.