Beveiligingsadvies

CVE-2019-14654

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2019-08-05 00:39:07
Laatst bijgewerkt 2024-08-05 00:19:41
Toegewezen door mitre
CVSS-score geen score
Status PUBLISHED

Beschrijving

In Joomla! 3.9.7 and 3.9.8, inadequate filtering allows users authorised to create custom fields to manipulate the filtering options and inject an unvalidated option. In other words, the filter attribute in subform fields allows remote code execution. This is fixed in 3.9.9.