First published: Tue Jan 12 2021(Updated: )
An issue was discovered in Joomla! 3.9.0 through 3.9.23. The lack of escaping in mod_breadcrumbs aria-label attribute allows XSS attacks.
Credit: security@joomla.org
Affected Software | Affected Version | How to fix |
---|---|---|
Joomla Joomla\! | >=3.9.0<=3.9.23 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-23124 is a vulnerability in Joomla! 3.9.0 through 3.9.23 that allows XSS attacks through the mod_breadcrumbs aria-label attribute.
CVE-2021-23124 has a severity rating of medium (6.1) according to CVSS.
CVE-2021-23124 affects Joomla! versions 3.9.0 through 3.9.23.
CVE-2021-23124 is associated with CWE-79, which is the Weakness for Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting').
To fix CVE-2021-23124, it is recommended to update Joomla! to the latest version available, which includes the necessary security patches.