Directory traversal vulnerability in the iNetLanka Multiple root (commultiroot) component 1.0 and 1.1 for Joomla! allows remote attackers to read arbitrary files via a .. (dot dot) in the controller parameter to index.php. NOTE: some of these details are obtained from third party information.
Inadequate validation of URLs could result into an invalid check whether an redirect URL is internal or not..
The pagination class includes arbitrary parameters in links, leading to cache poisoning attack vectors.
The mail template feature lacks an escaping mechanism, causing XSS vectors in multiple extensions.
Improper Access Controls allows backend users to overwrite their username when disallowed.
The stripImages and stripIframes methods didn't properly process inputs, leading to XSS vectors.
Various module chromes didn't properly process inputs, leading to XSS vectors.
Lack of output escaping in the id attribute of menu lists.
Improper Access Controls allows access to protected views.
Improper control of generation of code in the sourcerer extension for Joomla in versions before 11.0.0 lead to a remote code execution vulnerability.
Improper handling of identifiers lead to a SQL injection vulnerability in the quoteNameStr method of the database package. Please note: the affected method is a protected method. It has no usages in the original packages in neither the 2.x nor 3.x branch and therefore the vulnerability in question can not be exploited when using the original database class. However, classes extending the affected class might be affected, if the vulnerable method is used.
Insufficient state checks lead to a vector that allows to bypass 2FA checks.
The MFA management features did not properly terminate existing user sessions when a user's MFA methods have been modified.
Inadequate parsing of URLs could result into an open redirect.
Inadequate escaping of mail addresses lead to XSS vulnerabilities in various components.
Inadequate content filtering leads to XSS vulnerabilities in various components.
Impact The isMail transport in PHPMailer before 5.2.20 might allow remote attackers to pass extra parameters to the mail command and consequently execute arbitrary code by leveraging improper interaction between the escapeshellarg function and internal escaping performed in the mail function in PHP. NOTE: this vulnerability exists because of an incorrect fix for CVE-2016-10033.
This issue really emphasises that it's worth avoiding the built-in PHP mail() function entirely.
Patches Fixed in 5.2.20
Workarounds Send via SMTP to localhost instead of calling the mail() function.
References https://nvd.nist.gov/vuln/detail/CVE-2016-10045 See also https://nvd.nist.gov/vuln/detail/CVE-2016-10033
For more information If you have any questions or comments about this advisory: Open a private issue in the PHPMailer project
Cross-site scripting (XSS) vulnerability in libraries/idnaconvert/example.php in Joomla! 3.1.5 allows remote attackers to inject arbitrary web script or HTML via the lang parameter.
Multiple cross-site scripting (XSS) vulnerabilities in Joomla! 1.6.3 and earlier allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.
Multiple cross-site scripting (XSS) vulnerabilities in Joomla! before 1.6.4 allow remote attackers to inject arbitrary web script or HTML via (1) the query string to the comcontact component, as demonstrated by the Itemid parameter to index.php; (2) the query string to the comcontent component, as demonstrated by the filterorder parameter to index.php; (3) the query string to the comnewsfeeds component, as demonstrated by an arbitrary parameter to index.php; or (4) the option parameter in a reset.request action to index.php; and, when Internet Explorer or Konqueror is used, (5) allow remote attackers to inject arbitrary web script or HTML via the searchword parameter in a search action to index.php in the comsearch component.
SQL injection vulnerability in the TemplatePlaza.com TPDugg (comtpdugg) component 1.1 for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in a tags action to index.php.
SQL injection vulnerability in the Joomloc (comjoomloc) component 1.0 for Joomla allows remote attackers to execute arbitrary SQL commands via the id parameter in an edit task to index.php.
SQL injection vulnerability in the Lucy Games (comlucygames) component 1.5.4 for Joomla! allows remote attackers to execute arbitrary SQL commands via the gameid parameter in a game action to index.php. NOTE: some of these details are obtained from third party information.
SQL injection vulnerability in the updateOnePage function in components/combfsurveypro/controller.php in BF Survey Pro Free (combfsurveyprofree) 1.2.4, and other versions before 1.2.6, a component for Joomla!, allows remote attackers to execute arbitrary SQL commands via the table parameter in an updateOnePage action to index.php.
Joomla! before 1.5.4 does not configure .htaccess to apply certain security checks that "block common exploits" to SEF URLs, which has unknown impact and remote attack vectors.
The file caching implementation in Joomla! before 1.5.4 allows attackers to access cached pages via unknown attack vectors.
PHP remote file inclusion vulnerability in BSQ Sitestats (bsqsitestats) before 2.1.1 for Joomla! allows remote attackers to execute arbitrary PHP code via a URL in the mosConfigabsolutepath parameter.
An issue was discovered in Joomla! 4.0.0 through 4.2.6. A missing token check causes a CSRF vulnerability in the handling of post-installation messages.
Inadequate input validation for media selection fields lead to XSS vulnerabilities in various extensions.
An issue was discovered in Joomla! 4.0.0 through 4.2.4. A missing ACL check allows non super-admin users to access comactionlogs.