ZeroHour

CVE-2019-14654

CVSS 3.0
8.8 high
EPSS
2%p82
Published
()
Modified
Description

In Joomla! 3.9.7 and 3.9.8, inadequate filtering allows users authorised to create custom fields to manipulate the filtering options and inject an unvalidated option. In other words, the filter attribute in subform fields allows remote code execution. This is fixed in 3.9.9.

Vendors
joomla
Products
joomla\!
Ecosystems
Joomla
Vector
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.