SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2023-39971

Improper Neutralization of Input During Web Page Generation vulnerability in AcyMailing Enterprise component for Joomla allows XSS.

MEDIUM 6.1EPSS 0.40%

Does this matter?

Lower severity and a low EPSS score (0.40%). Track it; it rarely justifies an emergency change on its own.

Description

Improper Neutralization of Input During Web Page Generation vulnerability in AcyMailing Enterprise component for Joomla allows XSS. This issue affects AcyMailing Enterprise component for Joomla: 6.7.0-8.6.3.

CVSS 3.1
6.1 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
EPSS
0.40% probability · 33th percentile
CISA KEV
Not listed
Weakness
CWE-79
Affected
acymailing/acymailing
Source
security@joomla.org

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.