CVE-2009-1940: XSS
Published Jun 5, 2009
·Updated
Cross-site scripting (XSS) vulnerability in the administrator panel in the comusers core component for Joomla! 1.5.x through 1.5.10 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
Affected Software
11 affected components
Joomla joomla=1.5.5
Joomla joomla=1.5
Joomla joomla=1.5.7
Joomla joomla=1.5.9
Joomla joomla=1.5.3
Joomla joomla=1.5.10
Joomla joomla=1.5.2
Joomla joomla=1.5.8
Joomla joomla=1.5.1
Joomla joomla=1.5.4
Joomla joomla=1.5.6
Remediation
Patch Available
Patch Available
Event History
Jun 5, 2009
CVE Published
via MITRE·06:13 PM
Data Sourced
via MITRE·06:13 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2009-1940?
CVE-2009-1940 has been classified with a medium severity due to its potential for Cross-site scripting (XSS) attacks.
2
How do I fix CVE-2009-1940?
To fix CVE-2009-1940, update Joomla! to version 1.5.11 or later, which addresses this vulnerability.
3
What versions of Joomla! are affected by CVE-2009-1940?
CVE-2009-1940 affects Joomla! versions 1.5.x through 1.5.10.
4
What type of vulnerability is CVE-2009-1940?
CVE-2009-1940 is a Cross-site scripting (XSS) vulnerability found in the com_users core component.
5
Can CVE-2009-1940 lead to data compromises?
Yes, CVE-2009-1940 can allow remote attackers to inject arbitrary web scripts or HTML, potentially leading to data compromises.