CVE-2021-26030

MEDIUM6.1EPSS 9.3%

[20210401] - Core - Escape xss in logo parameter error pages

Published: 4/3/2025Modified: 5/20/2025

Description

An issue was discovered in Joomla! 3.0.0 through 3.9.25. Inadequate escaping allowed XSS attacks using the logo parameter of the default templates on error page

Affected packages (1)

CVSS scores

SourceVersionSeverityVector
osvCVSS 3.1MEDIUM6.1CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

References (2)