Joomla Security Notice :: April 14, 2021

Started by Jason, April 14, 2021, 04:34:20 PM

Previous topic - Next topic

0 Members and 1 Guest are viewing this topic.

Jason

Joomla has emailed a security announcement.  If you use Joomla for your site, please check your version and upgrade accordingly.

The announcement is available on their site here:

https://developer.joomla.org/security-centre.html

QuoteJoomla! Security News

________________________________________
[20210402] - Core - Inadequate filters on module layout settings
Posted: 13 Apr 2021 08:00 AM PDT
> Project: Joomla!
> SubProject: CMS
> Impact: Low
> Severity: Low
> Versions: 3.0.0 - 3.9.25
> Exploit type: LFI
> Reported Date: 2021-01-03
> Fixed Date: 2021-04-13
> CVE Number: CVE-2021-26031
Description
Inadequate filters on module layout settings could lead to an LFI.
Affected Installs
Joomla! CMS versions 3.0.0 - 3.9.25
Solution
Upgrade to version 3.9.26
Contact
The JSST at the Joomla! Security Centre.
Reported By: Lee Thao from Viettel Cyber Security
 
 

[20210401] - Core - Escape xss in logo parameter error pages
Posted: 13 Apr 2021 08:00 AM PDT
> Project: Joomla!
> SubProject: CMS
> Impact: Low
> Severity: Low
> Versions: 3.0.0 - 3.9.25
> Exploit type: XSS
> Reported Date: 2021-03-09
> Fixed Date: 2021-04-13
> CVE Number: CVE-2021-26030
Description
Inadequate escaping allowed XSS attacks using the logo parameter of the default templates on error pages.
Affected Installs
Joomla! CMS versions 3.0.0 - 3.9.25
Solution
Upgrade to version 3.9.26
Contact
The JSST at the Joomla! Security Centre.
Reported By: HOANG NGUYEN