CVE-2022-27913

MEDIUM6.1EPSS 0.15%

[20221002] - Core - RXSS through reflection of user input in headings

Published: 4/3/2025Modified: 5/20/2025

Description

An issue was discovered in Joomla! 4.2.0 through 4.2.3. Inadequate filtering of potentially malicious user input leads to reflected XSS vulnerabilities in various components.

Affected packages (1)

CVSS scores

SourceVersionSeverityVector
osvCVSS 3.1MEDIUM6.1CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

References (2)