There is always a great deal of Joomla! development activity underway and communicating with other developers in the community is essential. This site is a resource for anyone looking to build or maintain software based on the Joomla! platform.

  • Project: Joomla!
  • SubProject: All
  • Severity: Medium
  • Versions: 1.7.0 and all 1.6.x versions
  • Exploit type: XSS
  • Reported Date: 2011-August-02
  • Fixed Date: 2011-September-22

Description

Inadequate escaping leads to XSS vulnerability in com_search.

Affected Installs

Joomla! version 1.7.0 and all 1.6.x versions

Solution

Upgrade to the latest Joomla! version (1.7.1 or later)

Contact

The JSST at the Joomla! Security Centre.

Reported By: Aung Khant