VulnerabilityModified
CVE-2018-12711
An XSS issue was discovered in the language switcher module in Joomla!
MEDIUM 6.1EPSS 1.41%
Does this matter?
Lower severity and a low EPSS score (1.41%). Track it; it rarely justifies an emergency change on its own.
Description
An XSS issue was discovered in the language switcher module in Joomla! 1.6.0 through 3.8.8 before 3.8.9. In some cases, the link of the current language might contain unescaped HTML special characters. This may lead to reflective XSS via injection of arbitrary parameters and/or values on the current page URL.
- CVSS 3.0
- 6.1 MEDIUMCVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
- EPSS
- 1.41% probability · 71th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-79
- Affected
- joomla/joomla\!
- Source
- cve@mitre.org
References
- http://www.securityfocus.com/bid/104565Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1041244Third Party Advisory, VDB Entry
- https://developer.joomla.org/security-centre/740-20180602-core-xss-vulnerability-in-language-switcher-moduleVendor Advisory
- http://www.securityfocus.com/bid/104565Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1041244Third Party Advisory, VDB Entry
- https://developer.joomla.org/security-centre/740-20180602-core-xss-vulnerability-in-language-switcher-moduleVendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.