Joomla Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) Vulnerability - CVE-2018-6378 - Vulnerability Database

Joomla Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) Vulnerability - CVE-2018-6378

Medium
Reference: CVE-2018-6378
Title: Joomla Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) Vulnerability
Overview:

In Joomla Core before 3.8.8 inadequate filtering of file and folder names leads to various XSS attack vectors in the media manager.