Allele Security Alert
ASA-2019-00077
Identifier(s)
ASA-2019-00077, CVE-2019-7742
Title
Browserside mime-type sniffing causes XSS attack vectors
Vendor(s)
Open Source Matters, Inc
Product(s)
Joomla
Affected version(s)
Joomla 1.0.0 through 3.9.2
Fixed version(s)
Joomla 3.9.3
Proof of concept
Unknown
Description
A combination of specific webserver configurations, in connection with specific file types and browserside mime-type sniffing causes a XSS attack vector.
Technical details
Unknown
Credits
Hanno Böck
Reference(s)
Security Announcements
https://developer.joomla.org/security-centre.html
CVE-2019-7742
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-7742
CVE-2019-7742
https://nvd.nist.gov/vuln/detail/CVE-2019-7742
If there is any error in this alert or you wish a comprehensive analysis, let us know.
Last modified: February 13, 2019