CVE-2022-27913Cross-site Scripting in Joomla !

Severity
6.1MEDIUMNVD
EPSS
0.1%
top 64.88%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedOct 25
Latest updateOct 26

Description

An issue was discovered in Joomla! 4.2.0 through 4.2.3. Inadequate filtering of potentially malicious user input leads to reflected XSS vulnerabilities in various components.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:NExploitability: 2.8 | Impact: 2.7

Affected Packages2 packages

NVDjoomla/joomla_!4.0.04.2.3
CVEListV5joomla!_project/joomla!_cms4.2.0-4.2.3

🔴Vulnerability Details

2
GHSA
GHSA-8g63-qvh8-q593: An issue was discovered in Joomla! 42022-10-26
CVEList
[20221002] - Core - RXSS through reflection of user input in headings2022-10-25
CVE-2022-27913 — Cross-site Scripting in Joomla ! | cvebase