CVE-2015-6939: XSS
Published Sep 18, 2015
·Updated
Cross-site scripting (XSS) vulnerability in the login module in Joomla! 3.4.x before 3.4.4 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
Affected Software
12 affected components
Joomla Joomla\!=3.4.0
Joomla Joomla\!=3.4.0-alpha
Joomla Joomla\!=3.4.0-beta1
Joomla Joomla\!=3.4.0-beta2
Joomla Joomla\!=3.4.0-beta3
Joomla Joomla\!=3.4.0-rc1
Joomla Joomla\!=3.4.1
Joomla Joomla\!=3.4.1-rc1
Joomla Joomla\!=3.4.1-rc2
Joomla Joomla\!=3.4.2
Joomla Joomla\!=3.4.2-rc1
Joomla Joomla\!=3.4.3
Event History
Sep 18, 2015
CVE Published
via MITRE·04:00 PM
Data Sourced
via MITRE·04:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2015-6939?
CVE-2015-6939 is considered a medium severity vulnerability due to its potential for cross-site scripting (XSS) attacks.
2
How do I fix CVE-2015-6939?
To fix CVE-2015-6939, you should upgrade your Joomla installation to version 3.4.4 or later.
3
What types of attacks can occur due to CVE-2015-6939?
CVE-2015-6939 allows remote attackers to perform cross-site scripting (XSS) attacks by injecting arbitrary web scripts or HTML.
4
Which versions of Joomla are affected by CVE-2015-6939?
Joomla versions 3.4.0 through 3.4.3 are affected by CVE-2015-6939.
5
Is there a workaround for CVE-2015-6939?
There is no specific workaround for CVE-2015-6939 other than updating to the patched version of Joomla.