|
Subscribe to Joomla! Security Announcements - Click Here |
Tue 09 Sep 2008 |
|
DescriptionA flaw in JRequest exists where variables set with JRequest::setVar are not cleaned when fetching the variable at a later point in the request. This can result in variable injection (unwanted characters injected into returned data). 3PD Concerns3PD extensions which use JRequest do not need to change anything for proper function. Affected InstallsAll 1.5.x installs prior to and including 1.5.6 are affected. SolutionUpgrade to latest Joomla! version (1.5.7 or newer). Reported By Joomla! Development Coordinator Andrew Eddie. ContactThe JSST at the Joomla! Security Center. |
| Last Updated on Tuesday, 09 September 2008 16:26 |



