CVE-2024-21730: [20240702] - Core - Self-XSS in fancyselect list field layout
Published Jul 9, 2024
·Updated
The fancyselect list field layout does not correctly escape inputs, leading to a self-XSS vector.
Affected Software
2 affected components
Joomla Joomla\!>=4.0.0<4.4.6
Joomla Joomla\!>=5.0.0<5.1.2
Event History
Jul 9, 2024
CVE Published
via MITRE·04:15 PM
Data Sourced
via MITRE·04:15 PM
DescriptionWeakness
Data Sourced
via NVD·05:15 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-21730?
CVE-2024-21730 has a medium severity due to its potential for self-XSS exploitation.
2
How do I fix CVE-2024-21730?
To fix CVE-2024-21730, update your Joomla installation to version 4.4.6 or later, or 5.1.2 or later.
3
Which Joomla versions are affected by CVE-2024-21730?
CVE-2024-21730 affects Joomla versions between 4.0.0 and 4.4.6 and between 5.0.0 and 5.1.2.
4
What type of vulnerability is CVE-2024-21730?
CVE-2024-21730 is a self-XSS vulnerability due to improper input escaping in the fancyselect list field layout.
5
Can CVE-2024-21730 be exploited remotely?
CVE-2024-21730 is not a remote vulnerability as it requires user interaction to exploit.