CVE-2018-6378Cross-site Scripting in Joomla !

Severity
6.1MEDIUMNVD
EPSS
1.5%
top 18.89%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedMay 22
Latest updateMay 14

Description

In Joomla! Core before 3.8.8, inadequate filtering of file and folder names leads to various XSS attack vectors in the media manager.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:NExploitability: 2.8 | Impact: 2.7

Affected Packages1 packages

NVDjoomla/joomla_!< 3.8.8

🔴Vulnerability Details

2
GHSA
GHSA-fmq3-cg44-2w57: In Joomla! Core before 32022-05-14
CVEList
CVE-2018-6378: In Joomla! Core before 32018-05-22
CVE-2018-6378 — Cross-site Scripting in Joomla ! | cvebase