Percorso

Security Announcements

  1. [20180509] - Core - XSS vulnerability in the media manager
    • Project: Joomla!
    • SubProject: CMS
    • Impact: Low
    • Severity: Low
    • Versions: 1.5.0 through 3.8.7
    • Exploit type: XSS
    • Reported Date: 2017-October-28
    • Fixed Date: 2018-May-22
    • CVE Number: CVE-2018-6378

    Description

    Inadequate filtering of file and folder names lead to various XSS attack vectors in the media manager.

    Affected Installs

    Joomla! CMS versions 1.5.0 through 3.8.7

    Solution

    Upgrade to version 3.8.8

    Contact

    The JSST at the Joomla! Security Centre.

    Reported By: David Jardin, JSST
  2. [20180508] - Core - Possible XSS attack in the redirect method
    • Project: Joomla!
    • SubProject: CMS
    • Impact: Low
    • Severity: Low
    • Versions: 3.1.2 through 3.8.7
    • Exploit type: XSS
    • Reported Date: 2018-March-30
    • Fixed Date: 2018-May-22
    • CVE Number: CVE-2018-11328

    Description

    Under specific circumstances (a redirect issued with a URI containing a username and password when the Location: header cannot be used), a lack of escaping the user-info component of the URI could result in a XSS vulnerability.

    Affected Installs

    Joomla! CMS versions 3.1.2 through 3.8.7

    Solution

    Upgrade to version 3.8.8

    Contact

    The JSST at the Joomla! Security Centre.

    Reported By: David Jardin, JSST
  3. [20180507] - Core - Session deletion race condition
    • Project: Joomla!
    • SubProject: CMS
    • Impact: Medium
    • Severity: Low
    • Versions: 3.0.0 through 3.8.7
    • Exploit type: Session race condition
    • Reported Date: 2017-July-08
    • Fixed Date: 2018-May-22
    • CVE Number: CVE-2018-11324

    Description

    A long running background process, such as remote checks for core or extension updates, could create a race condition where a session which was expected to be destroyed would be recreated.

    Affected Installs

    Joomla! CMS versions 3.0.0 through 3.8.7

    Solution

    Upgrade to version 3.8.8

    Additional Resources

    Contact

    The JSST at the Joomla! Security Centre.

    Reported By: David Jardin, JSST
  4. [20180506] - Core - Filter field in com_fields allows remote code execution
    • Project: Joomla!
    • SubProject: CMS
    • Impact: Moderate
    • Severity: Low
    • Versions: 3.7.0 through 3.8.7
    • Exploit type: Remote Code Execution
    • Reported Date: 2018-May-14
    • Fixed Date: 2018-May-22
    • CVE Number: CVE-2018-11321

    Description

    Inadequate filtering allows users authorised to create custom fields to manipulate the filtering options and inject an unvalidated option.

    Affected Installs

    Joomla! CMS versions 3.7.0 through 3.8.7

    Solution

    Upgrade to version 3.8.8

    Contact

    The JSST at the Joomla! Security Centre.

    Reported By: Benjamin Trenkle, JSST
  5. [20180505] - Core - XSS Vulnerabilities & additional hardening
    • Project: Joomla!
    • SubProject: CMS
    • Impact: Moderate
    • Severity: Moderate
    • Versions: 3.0.0 through 3.8.7
    • Exploit type:XSS
    • Reported Date:2018-February-02 & 2018-March-27
    • Fixed Date: 2018-May-22
    • CVE Number: CVE-2018-11326

    Description

    Inadequate input filtering leads to multiple XSS vulnerabilities. Additionally, the default filtering settings could potentially allow users of the default Administrator user group to perform a XSS attack.

    Affected Installs

    Joomla! CMS versions 3.0.0 through 3.8.7

    Solution

    Upgrade to version 3.8.8

    Additional Resources

    Contact

    The JSST at the Joomla! Security Centre.

    Reported By: Kai Zhao of 3H Security Team & Zhouyuan Yang (FortiGuard Labs)
Documento senza titolo
Questo sito è a consultazione gratuita, finanziato esclusivamente dall’autore, privo di sponsor e non contiene pubblicità a pagamento.
Le informazioni presenti nel sito devono servire a migliorare, e non a sostituire, il rapporto medico-paziente.
Se hai problemi di salute, rivolgiti il prima possibile al tuo medico di fiducia.

powered by ©
Farmalem è un portale di servizio della salute e in tale ambito si pone l'obiettivo di rendere facilmente accessibili dati e notizie grazie ad una struttura chiara e semplice.
L’Autore di questo sito e Farmalem hanno un rapporto di consulenza gratuita fondato su anni di collaborazione medico-scientifica.
Copyright © Farmalem 2011 | All rights Reserved

 

Informativa

Questo sito o gli strumenti terzi da questo utilizzati si avvalgono di cookie necessari al funzionamento ed utili alle finalità illustrate nella cookie policy. Se vuoi saperne di più o negare il consenso a tutti o ad alcuni cookie, consulta la cookie policy.
Chiudendo questo banner, scorrendo questa pagina, cliccando su un link o proseguendo la navigazione in altra maniera, acconsenti all’uso dei cookie.