ZeroHour

CVE-2017-7987

CVSS 3.0
6.1 medium
EPSS
<1%p54
Published
()
Modified
Description

In Joomla! 3.2.0 through 3.6.5 (fixed in 3.7.0), inadequate escaping of file and folder names leads to XSS vulnerabilities in the template manager component.

Vendors
joomla
Products
joomla\!
Ecosystems
Joomla
Weakness
CWE-79
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

In the news

No ingested article mentions this CVE yet.