The administrator Modules list printed each module's position into the row's data-draggable-group attribute without escaping it. A user permitted to edit modules could store a crafted position value that breaks out of the attribute and runs arbitrary JavaScript in the browser of a Super User viewing the module list. This vulnerability affects the... Weiterlesen: Stored Cross-Site Scripting in Joomla Administrator Module List
Intelligence View
⚡ tsecurity.de Intelligence
Stored Cross-Site Scripting in Joomla Administrator Module List
The administrator Modules list printed each module's position into the row's data-draggable-group attribute without escaping it. A user permitted to edit…
Cyber Threat Intelligence & Forensik
ATT&CK-Navigator · IoC-Radar · Exploit-Belege