CVE-2017-7986Cross-site Scripting in Joomla !

Severity
6.1MEDIUMNVD
EPSS
0.0%
top 98.84%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedApr 25
Latest updateMay 17

Description

In Joomla! 1.5.0 through 3.6.5 (fixed in 3.7.0), inadequate filtering of specific HTML attributes leads to XSS vulnerabilities in various components.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:NExploitability: 2.8 | Impact: 2.7

Affected Packages1 packages

NVDjoomla/joomla_!107 versions+106

Patches

🔴Vulnerability Details

2
GHSA
GHSA-wmwp-8x8j-8wrf: In Joomla! 12022-05-17
CVEList
CVE-2017-7986: In Joomla! 12017-04-25

🕵️Threat Intelligence

3
Fortinet
Incomplete Patch: Another Joomla! Core XSS Vulnerability Is Discovered2018-05-25
Fortinet
Incomplete Patch: More Joomla! Core XSS Vulnerabilities Are Found2017-07-12
Fortinet
Multiple Joomla! Core XSS Vulnerabilities Are Discovered2017-05-04
CVE-2017-7986 — Cross-site Scripting in Joomla ! | cvebase