Joomla! Security Bypass and Cross-Site Scripting Vulnerability
RISK: Medium Risk
TYPE: Servers - Internet App Servers
Two vulnerability have been identified in Joomla!, which can be exploited by malicious people to bypass certain security restrictions and conduct cross-site scripting attacks.
Certain unspecified input is not properly sanitised before being returned to the user. This can be exploited to execute arbitrary HTML and script code in a user's browser session in context of an affected site.
This vulnerability is reported in versions prior to 1.7.3.- An error in the random number generation when resetting passwords can be exploited to change a user's password.
Impact
- Cross-Site Scripting
- Security Restriction Bypass
System / Technologies affected
- Joomla! 1.x
Solutions
Before installation of the software, please visit the software manufacturer web-site for more details.
- Update to version 1.7.3 or 1.5.25.
Vulnerability Identifier
- No CVE information is available
Source
Related Link
Share with