CVE-2021-26030Cross-site Scripting in Joomla !

Severity
6.1MEDIUMNVD
EPSS
33.6%
top 3.06%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedApr 14
Latest updateMay 24

Description

An issue was discovered in Joomla! 3.0.0 through 3.9.25. Inadequate escaping allowed XSS attacks using the logo parameter of the default templates on error page

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:NExploitability: 2.8 | Impact: 2.7

Affected Packages2 packages

NVDjoomla/joomla_!3.0.03.9.25
CVEListV5joomla!_project/joomla!_cms3.0.0-3.9.25

🔴Vulnerability Details

2
GHSA
GHSA-f8r2-5wfg-hq3j: An issue was discovered in Joomla! 32022-05-24
CVEList
[20210401] - Core - Escape xss in logo parameter error pages2021-04-14