First published: Wed Jul 26 2017(Updated: )
In Joomla! before 3.7.4, inadequate filtering of potentially malicious HTML tags leads to XSS vulnerabilities in various components.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Joomla | =1.5.0 | |
Joomla | =1.5.1 | |
Joomla | =1.5.2 | |
Joomla | =1.5.3 | |
Joomla | =1.5.4 | |
Joomla | =1.5.5 | |
Joomla | =1.5.6 | |
Joomla | =1.5.7 | |
Joomla | =1.5.8 | |
Joomla | =1.5.9 | |
Joomla | =1.5.10 | |
Joomla | =1.5.11 | |
Joomla | =1.5.12 | |
Joomla | =1.5.13 | |
Joomla | =1.5.14 | |
Joomla | =1.5.15 | |
Joomla | =1.5.15-rc | |
Joomla | =1.5.16 | |
Joomla | =1.5.17 | |
Joomla | =1.5.18 | |
Joomla | =1.5.19 | |
Joomla | =1.5.20 | |
Joomla | =1.5.21 | |
Joomla | =1.5.22 | |
Joomla | =1.5.23 | |
Joomla | =1.5.24 | |
Joomla | =1.5.25 | |
Joomla | =1.5.26 | |
Joomla | =1.6-alpha | |
Joomla | =1.6-alpha2 | |
Joomla | =1.6-beta1 | |
Joomla | =1.6-beta10 | |
Joomla | =1.6-beta11 | |
Joomla | =1.6-beta12 | |
Joomla | =1.6-beta13 | |
Joomla | =1.6-beta14 | |
Joomla | =1.6-beta15 | |
Joomla | =1.6-beta2 | |
Joomla | =1.6-beta3 | |
Joomla | =1.6-beta4 | |
Joomla | =1.6-beta5 | |
Joomla | =1.6-beta6 | |
Joomla | =1.6-beta7 | |
Joomla | =1.6-beta8 | |
Joomla | =1.6-beta9 | |
Joomla | =1.6-rc1 | |
Joomla | =1.6.0 | |
Joomla | =1.6.1 | |
Joomla | =1.6.2 | |
Joomla | =1.6.3 | |
Joomla | =1.6.4 | |
Joomla | =1.6.5 | |
Joomla | =1.6.6 | |
Joomla | =1.7.0 | |
Joomla | =1.7.1 | |
Joomla | =1.7.2 | |
Joomla | =1.7.3 | |
Joomla | =1.7.4 | |
Joomla | =1.7.5 | |
Joomla | =2.5.0 | |
Joomla | =2.5.1 | |
Joomla | =2.5.2 | |
Joomla | =2.5.3 | |
Joomla | =2.5.4 | |
Joomla | =2.5.5 | |
Joomla | =2.5.6 | |
Joomla | =2.5.7 | |
Joomla | =2.5.8 | |
Joomla | =2.5.9 | |
Joomla | =2.5.10 | |
Joomla | =2.5.11 | |
Joomla | =2.5.12 | |
Joomla | =2.5.13 | |
Joomla | =2.5.14 | |
Joomla | =2.5.15 | |
Joomla | =2.5.16 | |
Joomla | =2.5.17 | |
Joomla | =2.5.18 | |
Joomla | =2.5.19 | |
Joomla | =2.5.20 | |
Joomla | =2.5.21 | |
Joomla | =2.5.22 | |
Joomla | =2.5.23 | |
Joomla | =2.5.24 | |
Joomla | =2.5.25 | |
Joomla | =2.5.26 | |
Joomla | =2.5.27 | |
Joomla | =2.5.28 | |
Joomla | =3.0.0 | |
Joomla | =3.0.1 | |
Joomla | =3.0.2 | |
Joomla | =3.0.3 | |
Joomla | =3.0.4 | |
Joomla | =3.1.0 | |
Joomla | =3.1.1 | |
Joomla | =3.1.2 | |
Joomla | =3.1.3 | |
Joomla | =3.1.4 | |
Joomla | =3.1.5 | |
Joomla | =3.1.6 | |
Joomla | =3.2.0 | |
Joomla | =3.2.1 | |
Joomla | =3.2.2 | |
Joomla | =3.2.3 | |
Joomla | =3.2.4 | |
Joomla | =3.3.0 | |
Joomla | =3.3.1 | |
Joomla | =3.3.2 | |
Joomla | =3.3.3 | |
Joomla | =3.3.4 | |
Joomla | =3.3.5 | |
Joomla | =3.4.0 | |
Joomla | =3.4.0-alpha | |
Joomla | =3.4.0-beta1 | |
Joomla | =3.4.0-beta2 | |
Joomla | =3.4.0-beta3 | |
Joomla | =3.4.0-rc1 | |
Joomla | =3.4.1 | |
Joomla | =3.4.1-rc1 | |
Joomla | =3.4.1-rc2 | |
Joomla | =3.4.2-rc1 | |
Joomla | =3.4.3 | |
Joomla | =3.4.4 | |
Joomla | =3.4.5 | |
Joomla | =3.4.6 | |
Joomla | =3.4.7 | |
Joomla | =3.4.8 | |
Joomla | =3.4.8-rc | |
Joomla | =3.5.0 | |
Joomla | =3.5.0-beta | |
Joomla | =3.5.0-beta2 | |
Joomla | =3.5.0-beta3 | |
Joomla | =3.5.0-beta4 | |
Joomla | =3.5.0-beta5 | |
Joomla | =3.5.0-rc | |
Joomla | =3.5.0-rc2 | |
Joomla | =3.5.0-rc3 | |
Joomla | =3.5.0-rc4 | |
Joomla | =3.5.1 | |
Joomla | =3.5.1-rc | |
Joomla | =3.6.0 | |
Joomla | =3.6.0-alpha | |
Joomla | =3.6.0-beta1 | |
Joomla | =3.6.0-beta2 | |
Joomla | =3.6.0-rc | |
Joomla | =3.6.0-rc2 | |
Joomla | =3.6.1 | |
Joomla | =3.6.1-rc1 | |
Joomla | =3.6.1-rc2 | |
Joomla | =3.6.2 | |
Joomla | =3.6.3 | |
Joomla | =3.6.3-rc1 | |
Joomla | =3.6.3-rc2 | |
Joomla | =3.6.3-rc3 | |
Joomla | =3.6.4 | |
Joomla | =3.6.5 | |
Joomla | =3.7.0 | |
Joomla | =3.7.1 | |
Joomla | =3.7.2 | |
Joomla | =3.7.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-11612 has a medium severity rating due to its potential for XSS exploitation in affected Joomla! versions.
To fix CVE-2017-11612, update your Joomla! installation to version 3.7.4 or later, which addresses the vulnerability.
Joomla! versions prior to 3.7.4, including all versions starting from 1.5.0 up to 3.7.3, are affected by CVE-2017-11612.
CVE-2017-11612 is classified as a Cross-Site Scripting (XSS) vulnerability affecting multiple components of Joomla!
Attackers exploiting CVE-2017-11612 can inject malicious scripts into web pages viewed by other users, potentially compromising user data.