First published: Fri Sep 18 2015(Updated: )
Cross-site scripting (XSS) vulnerability in the login module in Joomla! 3.4.x before 3.4.4 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Joomla | =3.4.0 | |
Joomla | =3.4.0-alpha | |
Joomla | =3.4.0-beta1 | |
Joomla | =3.4.0-beta2 | |
Joomla | =3.4.0-beta3 | |
Joomla | =3.4.0-rc1 | |
Joomla | =3.4.1 | |
Joomla | =3.4.1-rc1 | |
Joomla | =3.4.1-rc2 | |
Joomla | =3.4.2 | |
Joomla | =3.4.2-rc1 | |
Joomla | =3.4.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2015-6939 is considered a medium severity vulnerability due to its potential for cross-site scripting (XSS) attacks.
To fix CVE-2015-6939, you should upgrade your Joomla installation to version 3.4.4 or later.
CVE-2015-6939 allows remote attackers to perform cross-site scripting (XSS) attacks by injecting arbitrary web scripts or HTML.
Joomla versions 3.4.0 through 3.4.3 are affected by CVE-2015-6939.
There is no specific workaround for CVE-2015-6939 other than updating to the patched version of Joomla.