CVE-2018-11326: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
(updated )
An issue was discovered in Joomla! Core before 3.8.8. Inadequate input filtering leads to a multiple XSS vulnerabilities. Additionally, the default filtering settings could potentially allow users of the default Administrator user group to perform a XSS attack.
References
- developer.joomla.org/security-centre/733-20180505-core-xss-vulnerabilities-additional-hadering.html
- github.com/advisories/GHSA-g3m5-vvj7-xrwv
- nvd.nist.gov/vuln/detail/CVE-2018-11326
- web.archive.org/web/20210124173032/http://www.securityfocus.com/bid/104270
- web.archive.org/web/20211129145422/http://www.securitytracker.com/id/1040966
Detect and mitigate CVE-2018-11326 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →