Joomla! patches XSS flaws that could lead to remote code execution
ID: ab0a435b-ab38-5a91-bf74-9236753dbe22
STIX ID: report--ab0a435b-ab38-5a91-bf74-9236753dbe22
Feed Name: Malwarebytes Blog
Threat Score
Joomla released security updates addressing five vulnerabilities (CVE-2024-21722–CVE-2024-21726) impacting the CMS and framework—issues include improper MFA session termination, open redirect, multiple XSS flaws (some enabling RCE when an admin is tricked), and insufficient input/escaping in components; administrators are urged to upgrade to 3.10.15-elts, 4.4.3, or 5.0.3 and follow CMS hardening practices (minimal extensions, 2FA, WAF, restricted uploads).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
