First published: Tue Feb 06 2018(Updated: )
Cross-site scripting (XSS) vulnerability in assets/js/vm2admin.js in the VirtueMart component before 3.0.8 for Joomla! allows remote attackers to inject arbitrary web script or HTML via vectors involving a "double encode combination of first_name, last_name and company."
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
VirtueMart Joomla Ecommerce Edition CMS | <3.0.8 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2015-3619 is classified as a medium-severity cross-site scripting (XSS) vulnerability.
To mitigate CVE-2015-3619, update VirtueMart to version 3.0.8 or later.
CVE-2015-3619 affects users of VirtueMart versions prior to 3.0.8 on Joomla!.
CVE-2015-3619 facilitates cross-site scripting (XSS) attacks that allow remote code execution.
CVE-2015-3619 involves the assets/js/vm2admin.js file within the VirtueMart component.