First published: Tue Jul 09 2024(Updated: )
The Custom Fields component not correctly filter inputs, leading to a XSS vector.
Credit: security@joomla.org
Affected Software | Affected Version | How to fix |
---|---|---|
>=3.7.0<3.10.16 | ||
>=4.0.0<4.4.6 | ||
>=5.0.0<5.1.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-26278 is classified as a high severity vulnerability due to its potential for exploiting XSS attacks.
To fix CVE-2024-26278, upgrade Joomla to the latest patched version available beyond 3.10.16, 4.4.6, or 5.1.2.
CVE-2024-26278 affects Joomla versions between 3.7.0 and 3.10.16, 4.0.0 and 4.4.6, and 5.0.0 and 5.1.2.
CVE-2024-26278 is an XSS (Cross-Site Scripting) vulnerability that arises from improper input filtering in the Custom Fields component.
While there may not be a specific exploit publicly documented for CVE-2024-26278, the nature of XSS vulnerabilities generally allows attackers to execute malicious scripts.