CVE-2022-23801Cross-site Scripting in Joomla !

Severity
6.1MEDIUMNVD
EPSS
0.8%
top 25.62%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMar 30
Latest updateMar 31

Description

An issue was discovered in Joomla! 4.0.0 through 4.1.0. Possible XSS atack vector through SVG embedding in com_media.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:NExploitability: 2.8 | Impact: 2.7

Affected Packages2 packages

NVDjoomla/joomla_!4.0.04.1.0
CVEListV5joomla!_project/joomla!_cms4.0.0-4.1.0

🔴Vulnerability Details

2
GHSA
GHSA-ffxv-f8p3-jqr2: An issue was discovered in Joomla! 42022-03-31
CVEList
[20220309] - Core - XSS attack vector through SVG2022-03-30
CVE-2022-23801 — Cross-site Scripting in Joomla ! | cvebase