The toolbar link layout printed a button's id, CSS class and URL straight into HTML attributes without escaping them. Where any of those values derive from request or user-supplied data, an attacker could break out of the attribute and run arbitrary JavaScript in the browser of an administrator viewing the page. This vulnerability affects the... Weiterlesen: Cross-Site Scripting in Joomla Toolbar Link Layout
Intelligence View
⚡ tsecurity.de Intelligence
Cross-Site Scripting in Joomla Toolbar Link Layout
The toolbar link layout printed a button's id, CSS class and URL straight into HTML attributes without escaping them. Where any of those values derive from…
Cyber Threat Intelligence & Forensik
ATT&CK-Navigator · IoC-Radar · Exploit-Belege