• Project: Joomla!
  • SubProject: com_users
  • Severity: Moderate
  • Versions: 1.5.10 and all previous 1.5 releases
  • Exploit type: XSS
  • Reported Date: 2009-April-30
  • Fixed Date: 2009-June-02


A XSS vulnerability exists in the user view of com_users in the administrator panel.

Affected Installs

All 1.5.x installs prior to and including 1.5.10 are affected.


Upgrade to latest Joomla! version (1.5.11 or newer).


The JSST at the Joomla! Security Centre.

Reported By: Airton Torres