CyberRota Analysis
AI-GeneratedJoomla's InputFilter is vulnerable due to an XSS filter bypass stemming from an HTML5 entity decode mismatch, affecting versions 1.5.0-5.4.8 and 6.0.0-6.1.3. This flaw allows attackers to inject malicious scripts via improperly sanitized attribute values, potentially leading to unauthorized access or data manipulation. Organizations using these Joomla versions should prioritize patching this vulnerability to mitigate the risk of XSS attacks.
Original NVD Description
Joomla! Core - [20260915] - Core - XSS filter bypass in InputFilter via HTML5 entity decode mismatch in Joomla 1.5.0-5.4.8, 6.0.0-6.1.3 - The checkAttribute method normalized an attribute value before testing it against the "javascript:" scheme regex, however without decoding HTML5 entities beforehand, causing an XSS vector.
Related CVEs
Other vulnerabilities affecting the same vendor(s)