First published: Wed Mar 30 2022(Updated: )
An issue was discovered in Joomla! 3.7.0 through 3.10.6. Lack of input validation could allow an XSS attack using com_fields.
Credit: security@joomla.org
Affected Software | Affected Version | How to fix |
---|---|---|
Joomla Joomla\! | >=3.7.0<=3.10.6 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-23796 is a vulnerability discovered in Joomla! 3.7.0 through 3.10.6 that allows for an XSS attack using com_fields due to a lack of input validation.
The severity of CVE-2022-23796 is medium, with a severity value of 6.1.
CVE-2022-23796 affects Joomla! software versions 3.7.0 through 3.10.6 by enabling an XSS attack through the com_fields component.
To fix CVE-2022-23796, it is recommended to update Joomla! to a version beyond 3.10.6 and apply the necessary patches.
More information about CVE-2022-23796 can be found at the Joomla! Security Centre.