- Project: Joomla!
- SubProject: Site client
- Severity: Low
- Versions: 1.5.10 and all previous 1.5 releases
- Exploit type: XSS
- Reported Date: 2009-May-05
- Fixed Date: 2009-June-02
Some values were output from the database without being properly escaped. Most strings in question were sourced from the administrator panel.
All 1.5.x installs prior to and including 1.5.10 are affected.
Upgrade to latest Joomla! version (1.5.11 or newer).
The JSST at the Joomla! Security Center.