First published: Tue May 25 2021(Updated: )
An issue was discovered in Joomla! 3.0.0 through 3.9.26. HTML was missing in the executable block list of MediaHelper::canUpload, leading to XSS attack vectors.
Credit: security@joomla.org
Affected Software | Affected Version | How to fix |
---|---|---|
Joomla Joomla\! | >=3.0.0<=3.9.26 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-26032 is a vulnerability discovered in Joomla! 3.0.0 through 3.9.26 that allows for XSS attack vectors due to missing HTML in the executable block list of MediaHelper::canUpload.
CVE-2021-26032 has a severity rating of 6.1 (medium).
CVE-2021-26032 affects Joomla! versions 3.0.0 through 3.9.26.
The XSS attack vectors in CVE-2021-26032 can be exploited by injecting malicious code into the executable block list of MediaHelper::canUpload.
Yes, a fix for CVE-2021-26032 is available. It is recommended to update Joomla! to a version that includes the fix.