Joomla Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) Vulnerability - CVE-2017-7987 - Vulnerability Database
Joomla Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) Vulnerability - CVE-2017-7987
Medium
Reference:
CVE-2017-7987
Title:
Joomla Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) Vulnerability
Overview:
In Joomla 3.2.0 through 3.6.5 (fixed in 3.7.0) inadequate escaping of file and folder names leads to XSS vulnerabilities in the template manager component.