Allele Security Alert
ASA-2019-00135
Identifier(s)
ASA-2019-00135, CVE-2019-9714
Title
Cross-Site Scripting (XSS) in media form field
Vendor(s)
Open Source Matters, Inc
Product(s)
Joomla! CMS
Affected version(s)
Joomla! CMS versions 3.2.0 through 3.9.3
Fixed version(s)
Joomla! CMS version 3.9.4
Proof of concept
Unknown
Description
The media form field lacks escaping, leading to a Cross-Site Scripting (XSS) vulnerability.
Technical details
Unknown
Credits
Fouad Maakor
Reference(s)
Security Announcements
https://developer.joomla.org/security-centre/
[20190303] – Core – XSS in media form field
https://developer.joomla.org/security-centre/774-20190303-core-xss-in-media-form-field.html
CVE-2019-9714
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-9714
CVE-2019-9714
https://nvd.nist.gov/vuln/detail/CVE-2019-9714
If there is any error in this alert or you wish a comprehensive analysis, let us know.
Last modified: March 14, 2019