• Project: Joomla!
  • SubProject: com_users
  • Severity: Moderate
  • Versions: 1.5.10 and all previous 1.5 releases
  • Exploit type: XSS
  • Reported Date: 2009-April-30
  • Fixed Date: 2009-June-02

Description

A XSS vulnerability exists in the user view of com_users in the administrator panel.

Affected Installs

All 1.5.x installs prior to and including 1.5.10 are affected.

Solution

Upgrade to latest Joomla! version (1.5.11 or newer).

Contact

The JSST at the Joomla! Security Centre.

Reported By: Airton Torres