- Project: Joomla!
- SubProject: com_weblinks
- Severity: Moderate
- Versions: 1.5.7 and all previous 1.5 releases
- Exploit type: XSS
- Reported Date: 2008-November-9
- Fixed Date: 2008-November-10
com_weblinks allows raw HTML into the title and description tags for weblink submissions (from both the administrator and site submission forms).
All 1.5.x installs prior to and including 1.5.7 are affected.
Upgrade to latest Joomla! version (1.5.8 or newer).
The JSST at the Joomla! Security Centre.