In Joomla! before 3.7.4, inadequate filtering of potentially malicious HTML tags leads to XSS vulnerabilities in various components.
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
Link | Tags |
---|---|
https://developer.joomla.org/security-centre/701-20170605-core-xss-vulnerability.html | vendor advisory |
http://www.securitytracker.com/id/1039014 | vdb entry third party advisory |