CVE-2019-16725: XSS
Published Sep 24, 2019
·Updated
In Joomla! 3.x before 3.9.12, inadequate escaping allowed XSS attacks using the logo parameter of the default templates.
Affected Software
2 affected componentsFixes available
composer/joomla/joomla-cms>=3.0.0<3.9.12
3.9.12
Joomla Joomla\!>=3.0.0<3.9.12
Event History
Sep 24, 2019
CVE Published
via MITRE·08:06 PM
Data Sourced
via MITRE·08:06 PM
Description
May 24, 2022
Advisory Published
04:56 PM
Frequently Asked Questions
1
What is the severity of CVE-2019-16725?
CVE-2019-16725 is categorized as a medium severity vulnerability due to its exploitation potential for XSS attacks.
2
How do I fix CVE-2019-16725?
To fix CVE-2019-16725, upgrade Joomla! to version 3.9.12 or later.
3
Which versions of Joomla! are affected by CVE-2019-16725?
Joomla! versions from 3.0.0 to 3.9.11 are affected by CVE-2019-16725.
4
What type of vulnerability is CVE-2019-16725?
CVE-2019-16725 is a cross-site scripting (XSS) vulnerability.
5
What is the impact of CVE-2019-16725?
The impact of CVE-2019-16725 includes the possibility for an attacker to inject malicious scripts via the logo parameter.