First published: Thu Jul 01 2010(Updated: )
Cross-site scripting (XSS) vulnerability in the JExtensions JE Awd Song (com_awd_song) component for Joomla! allows remote attackers to inject arbitrary web script or HTML via the song review field, which is not properly handled in a view action to index.php.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
harmistechnology com Awd Song | ||
Joomla |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2010-2613 is classified as medium due to the potential for remote code execution via cross-site scripting.
To fix CVE-2010-2613, you should update the JExtensions JE Awd Song component to the latest version that addresses this vulnerability.
CVE-2010-2613 affects Joomla! systems that have the JExtensions JE Awd Song component installed.
Yes, CVE-2010-2613 can lead to data theft as an attacker can exploit the XSS vulnerability to inject malicious scripts.
CVE-2010-2613 can be exploited by remote attackers who can submit input to the song review field without proper validation.