Joomla Security Notice :: Sept 9, 2015

Started by Jason, September 09, 2015, 07:22:33 PM

Previous topic - Next topic

0 Members and 1 Guest are viewing this topic.

Jason

Joomla sent out a security notice today:

Click here to read.

Quote
Joomla! Security News
________________________________________
[20150908] - Core - XSS Vulnerability
Posted: 08 Sep 2015 07:25 PM PDT
> Project: Joomla!
> SubProject: CMS
> Severity: Low
> Versions: 3.4.0 through 3.4.3
> Exploit type: XSS Vulnerability
> Reported Date: 2015-August-18
> Fixed Date: 2015-September-08
> CVE Number: requested
Description
Inadequate escaping leads to XSS vulnerability in login module.
Affected Installs
Joomla! CMS versions 3.4.0 through 3.4.3
Solution
Upgrade to version 3.4.4