CVE-2024-26279

The wrapper extensions do not correctly validate inputs, leading to XSS vectors.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:joomla:joomla\!:*:*:*:*:*:*:*:*
cpe:2.3:a:joomla:joomla\!:*:*:*:*:*:*:*:*
cpe:2.3:a:joomla:joomla\!:*:*:*:*:*:*:*:*

History

19 Jul 2024, 18:53

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 6.1
References () https://developer.joomla.org/security-centre/938-20240704-core-xss-in-wrapper-extensions.html - () https://developer.joomla.org/security-centre/938-20240704-core-xss-in-wrapper-extensions.html - Vendor Advisory
CPE cpe:2.3:a:joomla:joomla\!:*:*:*:*:*:*:*:*
First Time Joomla joomla\!
Joomla

10 Jul 2024, 09:15

Type Values Removed Values Added
References
  • {'url': 'https://developer.joomla.org/security-centre/929-20240205-core-inadequate-content-filtering-within-the-filter-code.html', 'source': 'security@joomla.org'}
  • () https://developer.joomla.org/security-centre/938-20240704-core-xss-in-wrapper-extensions.html -
Summary
  • (es) El filtrado de contenido inadecuado genera vulnerabilidades XSS en varios componentes.
Summary (en) Inadequate content filtering leads to XSS vulnerabilities in various components. (en) The wrapper extensions do not correctly validate inputs, leading to XSS vectors.

09 Jul 2024, 17:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-07-09 17:15

Updated : 2024-07-19 18:53


NVD link : CVE-2024-26279

Mitre link : CVE-2024-26279

CVE.ORG link : CVE-2024-26279


JSON object : View

Products Affected

joomla

  • joomla\!
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')