CVE-2022-23800Cross-site Scripting in Joomla Filter

Severity
6.1MEDIUMNVD
EPSS
0.7%
top 28.01%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMar 30
Latest updateMar 31

Description

An issue was discovered in Joomla! 4.0.0 through 4.1.0. Inadequate content filtering leads to XSS vulnerabilities in various components.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:NExploitability: 2.8 | Impact: 2.7

Affected Packages4 packages

NVDjoomla/joomla_!4.0.04.1.0
CVEListV5joomla!_project/joomla!_cms4.0.0-4.1.0
CVEListV5joomla!_project/joomla_filter1.0.0-1.4.3 & 2.0.0
Packagistjoomla/filter2.0.02.0.1+1

🔴Vulnerability Details

3
OSV
Cross-site Scripting (XSS) within joomla/filter class2022-03-31
GHSA
Cross-site Scripting (XSS) within joomla/filter class2022-03-31
CVEList
[20220308] - Core - Inadequate content filtering within the filter code2022-03-30
CVE-2022-23800 — Cross-site Scripting in Joomla Filter | cvebase