CVE-2023-39971: Extension - acymailing.com - XSS in AcyMailing Enterprise component for Joomla 6.7.0-8.6.3
Published Aug 17, 2023
·Updated
Improper Neutralization of Input During Web Page Generation vulnerability in AcyMailing Enterprise component for Joomla allows XSS. This issue affects AcyMailing Enterprise component for Joomla: 6.7.0-8.6.3.
Affected Software
1 affected component
AcyMailing Acymailing Joomla\!>=6.7.0<8.7.0
Event History
Aug 17, 2023
CVE Published
08:06 PM
Data Sourced
08:06 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2023-39971.
2
What is the severity of CVE-2023-39971?
The severity of CVE-2023-39971 is medium (6.1).
3
What is the affected software for CVE-2023-39971?
The affected software for CVE-2023-39971 is AcyMailing Enterprise component for Joomla version 6.7.0 to 8.6.3.
4
What is the CWE category for CVE-2023-39971?
The CWE category for CVE-2023-39971 is CWE-79 (Improper Neutralization of Input During Web Page Generation).
5
How can I fix CVE-2023-39971?
To fix CVE-2023-39971, it is recommended to update AcyMailing Enterprise component for Joomla to version 8.7.0 or higher.