CVE-2020-13763: High severity joomla vulnerability
Published Jun 2, 2020
·Updated
In Joomla! before 3.9.19, the default settings of the global textfilter configuration do not block HTML inputs for Guest users.
Affected Software
5 affected components
Joomla Joomla\!>=2.5.1<3.9.19
Joomla Joomla\!=2.5.0
Joomla Joomla\!=2.5.0-beta1
Joomla Joomla\!=2.5.0-beta2
Joomla Joomla\!=2.5.0-rc1
Event History
Jun 2, 2020
CVE Published
via MITRE·07:24 PM
Data Sourced
via MITRE·07:24 PM
Description
Frequently Asked Questions
1
What is the vulnerability impact of CVE-2020-13763?
CVE-2020-13763 allows Guest users to submit unfiltered HTML, potentially leading to XSS attacks.
2
How can I remediate CVE-2020-13763?
To fix CVE-2020-13763, upgrade Joomla! to version 3.9.19 or later.
3
Who is affected by CVE-2020-13763?
CVE-2020-13763 affects all Joomla! installations before version 3.9.19.
4
Is CVE-2020-13763 a critical vulnerability?
CVE-2020-13763 is considered a moderate severity vulnerability due to its potential for XSS.
5
What versions of Joomla! are vulnerable to CVE-2020-13763?
Joomla! versions from 2.5.0 up to, but not including, 3.9.19 are vulnerable to CVE-2020-13763.