VulnerabilityModified
CVE-2019-12766
This leads to XSS attack vectors.
MEDIUM 6.1EPSS 0.92%
Does this matter?
Lower severity and a low EPSS score (0.92%). Track it; it rarely justifies an emergency change on its own.
Description
An issue was discovered in Joomla! before 3.9.7. The subform fieldtype does not sufficiently filter or validate input of subfields. This leads to XSS attack vectors.
- CVSS 3.1
- 6.1 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
- EPSS
- 0.92% probability · 58th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-79
- Affected
- joomla/joomla\!
- Source
- cve@mitre.org
References
- http://www.securityfocus.com/bid/108735Broken Link, Third Party Advisory, VDB Entry
- https://developer.joomla.org/security-centre/784-20190602-core-xss-in-subform-fieldVendor Advisory
- http://www.securityfocus.com/bid/108735Broken Link, Third Party Advisory, VDB Entry
- https://developer.joomla.org/security-centre/784-20190602-core-xss-in-subform-fieldVendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.