Joomla Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) Vulnerability - CVE-2018-6380
In Joomla before 3.8.4 lack of escaping in the module chromes leads to XSS vulnerabilities in the module system.
In Joomla before 3.8.4 lack of escaping in the module chromes leads to XSS vulnerabilities in the module system.