CVE-2023-28733

Publication date

2023-03-30 11:27:40

Family

NCSC.ch

State

PUBLISHED

Description

AnyMailing Joomla Plugin is vulnerable to stored cross site scripting (XSS) in templates and emails of AcyMailing, exploitable without authentication when access is granted to the campaigns creation on front-office. This issue affects AnyMailing Joomla PluginĀ Enterprise in versions below 8.3.0.