Beveiligingsadvies

CVE-2026-85190

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2026-09-14 06:18:26
Laatst bijgewerkt 2026-09-15 04:46:08
Toegewezen door Joomla
CVSS-score 7.5
Status PUBLISHED

Beschrijving

Joomla Extension - regularlabs.com - Privileged stored XSS via class option in Quick Index extension for Joomla < 5.0.5 - Quick Index inserts configurable class values into generated HTML without escaping them for an HTML attribute. A crafted value can close the intended class attribute and introduce a new attribute. Joomla's content filter cannot reliably prevent this because Quick Index creates the executable HTML after the authored plugin syntax was filtered.