CVE-2024-27186 — Cross-site Scripting in Joomla !
Severity
6.1MEDIUMNVD
EPSS
0.1%
top 74.42%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedAug 20
Description
The mail template feature lacks an escaping mechanism, causing XSS vectors in multiple extensions.
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:NExploitability: 2.8 | Impact: 2.7