Joomla's InputFilter did not decode attribute values the way a browser does before checking them for dangerous URL schemes. HTML5 entities, unterminated numeric references and whitespace inside data URIs bypassed the filter, allowing stored XSS. This vulnerability affects the following application versions: Joomla 2.5.0 Joomla 2.5.1 Joomla 2.5.2... Weiterlesen: Cross-Site Scripting filter bypass in Joomla InputFilter
Intelligence View
⚡ tsecurity.de Intelligence
Cross-Site Scripting filter bypass in Joomla InputFilter
Joomla's InputFilter did not decode attribute values the way a browser does before checking them for dangerous URL schemes. HTML5 entities, unterminated…
Cyber Threat Intelligence & Forensik
ATT&CK-Navigator · IoC-Radar · Exploit-Belege