CVE-2020-13761: XSS
Published Jun 2, 2020
·Updated
In Joomla! before 3.9.19, lack of input validation in the heading tag option of the "Articles - Newsflash" and "Articles - Categories" modules allows XSS.
Affected Software
5 affected components
Joomla Joomla\!>=3.0.1<3.9.19
Joomla Joomla\!=3.0.0
Joomla Joomla\!=3.0.0-alpha1
Joomla Joomla\!=3.0.0-alpha2
Joomla Joomla\!=3.0.0-beta1
Event History
Jun 2, 2020
CVE Published
via MITRE·07:25 PM
Data Sourced
via MITRE·07:25 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2020-13761?
CVE-2020-13761 is classified as a low-severity vulnerability.
2
How do I fix CVE-2020-13761?
To fix CVE-2020-13761, upgrade Joomla! to version 3.9.19 or later.
3
What systems are affected by CVE-2020-13761?
CVE-2020-13761 affects Joomla! versions prior to 3.9.19 and other specific versions including 3.0.x.
4
What type of vulnerability is CVE-2020-13761?
CVE-2020-13761 is an XSS (Cross-Site Scripting) vulnerability.
5
How does CVE-2020-13761 exploit Joomla! installations?
CVE-2020-13761 exploits Joomla! by allowing attackers to inject malicious scripts through the heading tag option in specific modules.