- Project: Joomla!
 - SubProject: CMS
 - Impact: Low
 - Severity: Low
 - Probability: Low
 - Versions: 4.0.0-4.4.5, 5.0.0-5.1.1
 - Exploit type: XSS
 - Reported Date: 2024-06-03
 - Fixed Date: 2024-07-09
 - CVE Number: CVE-2024-21730
 
Description
The fancyselect list field layout does not correctly escape inputs, leading to a self-XSS vector.
Affected Installs
Joomla! CMS versions 4.0.0-4.4.5, 5.0.0-5.1.1
Solution
Upgrade to version 4.4.6 or 5.1.2
Contact
The JSST at the Joomla! Security Centre.
Reported By:  Jesper den Boer