CVE-2015-7324: XSS
Multiple cross-site scripting (XSS) vulnerabilities in helpers/comment.php in the StackIdeas Komento (comkomento) component before 2.0.5 for Joomla! allow remote attackers to inject arbitrary web script or HTML via the (1) img or (2) url tag of a new comment.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2015-7324?
The CVE-2015-7324 vulnerability is categorized as a moderate severity cross-site scripting (XSS) issue.
How do I fix CVE-2015-7324?
To fix CVE-2015-7324, upgrade the Komento component to version 2.0.5 or later.
What types of XSS attacks are possible with CVE-2015-7324?
CVE-2015-7324 allows remote attackers to perform reflected XSS attacks using img or url tags in comments.
Which versions of Joomla! are affected by CVE-2015-7324?
CVE-2015-7324 affects the Komento component for Joomla! versions prior to 2.0.5.
Can CVE-2015-7324 lead to complete site compromise?
Yes, exploits of CVE-2015-7324 may allow attackers to inject malicious scripts, potentially leading to complete site compromise.