Subscribe to Joomla! Security Announcements - Click Here

Mon

10

Nov

2008

[20081102] - Core - com_weblinks XSS vulnerability
Monday, 10 November 2008 23:56
  • Project: Joomla!
  • SubProject: com_weblinks
  • Severity:moderate
  • Versions: 1.5.7 and all previous 1.5 releases
  • Exploit type: XSS
  • Reported Date: 2008-November-9
  • Fixed Date: 2008-November-10

Description

com_weblinks allows raw HTML into the title and description tags for weblink submissions (from both the administrator and site submission forms). 

Affected Installs

All 1.5.x installs prior to and including 1.5.7 are affected.

Solution

Upgrade to latest Joomla! version (1.5.8 or newer).

Reported By Gergo Erdosi

Contact

The JSST at the Joomla! Security Center.