The generic audio and video output layouts in Joomla 6.1 escaped only the src attribute and printed every other attribute value, attribute name and the type raw. A content editor who can set media custom field values (such as a video poster) can inject JavaScript that runs in the browser of any visitor or administrator viewing the item. This... Weiterlesen: Cross-Site Scripting in Joomla Media Field Audio/Video Layouts
Intelligence View
⚡ tsecurity.de Intelligence
Cross-Site Scripting in Joomla Media Field Audio/Video Layouts
The generic audio and video output layouts in Joomla 6.1 escaped only the src attribute and printed every other attribute value, attribute name and the type…
Cyber Threat Intelligence & Forensik
ATT&CK-Navigator · IoC-Radar · Exploit-Belege