Vulnerability Bulletins

[20170404] - Core - XSS Vulnerability

   
Affected software Joomla
 
Project: Joomla! SubProject: CMS Severity: Low Versions: 1.5.0 through 3.6.5 Exploit type: XSS Reported Date: 2017-February-22 Fixed Date: 2017-April-25 CVE Number: CVE-2017-7986 Description Inadequate filtering of specific HTML attributes leads to XSS vulnerabilities in various components. Affected Installs Joomla! CMS versions 1.5.0 through 3.6.5 Solution Upgrade to version 3.7.0 Contact The JSST at the Joomla! Security Centre. Reported By: Fortinets FortiGuard Labs

More info:

http://feeds.joomla.org/~r/JoomlaSecurityNews/~3/eeKSY-lLIXw/686-20170404-core-xss-vulnerability.html