首頁 News Feeds Joomla! Security News
  • Narrow screen resolution
  • Wide screen resolution
  • Wide screen resolution
  • Increase font size
  • Default font size
  • Decrease font size
  • default style
  • blue style
  • green style
週日, 13 七月, 2025

Deprecated: Function ereg() is deprecated in /home/adingp/public_html/a1/modules/mod_photofader/mod_photofader.php on line 192

Deprecated: Function ereg() is deprecated in /home/adingp/public_html/a1/modules/mod_photofader/mod_photofader.php on line 203
Newsfeeds
Security Announcements


  • [20200605] - Core - CSRF in com_postinstall
    • Project: Joomla!
    • SubProject: CMS
    • Impact: Low
    • Severity: Low
    • Versions: 3.7.0-3.9.18
    • Exploit type: CSRF
    • Reported Date: 2020-May-08
    • Fixed Date: 2020-June-02
    • CVE Number: CVE-2020-13760

    Description

    Missing token checks in com_postinstall cause CSRF vulnerabilities.

    Affected Installs

    Joomla! CMS versions 3.7.0 - 3.9.18

    Solution

    Upgrade to version 3.9.19

    Contact

    The JSST at the Joomla! Security Centre.

    Reported By: Bui Duc Anh Khoa from Viettel Cyber Security


  • [20200604] - Core - XSS in jQuery.htmlPrefilter
    • Project: Joomla!
    • SubProject: CMS
    • Impact: Low
    • Severity: Moderate
    • Versions: 3.0.0-3.9.18
    • Exploit type: XSS
    • Reported Date: 2020-April-10
    • Fixed Date: 2020-June-02
    • CVE Number: CVE-2020-11022 and CVE-2020-11023

    Description

    The jQuery project released version 3.5.0, and as part of that, disclosed two security vulnerabilities that affect all prior versions. As mentioned in the jQuery blog, both are "[...] security issues in jQuery’s DOM manipulation methods, as in .html(), .append(), and the others."

    The Drupal project has backported the relevant fixes back to jQuery 1.x and Joomla has adopted that patch.

    Affected Installs

    Joomla! CMS versions 3.0.0 - 3.9.18

    Solution

    Upgrade to version 3.9.19

    Contact

    The JSST at the Joomla! Security Centre.

    Reported By: David Jardin, JSST


  • [20200603] - Core - XSS in com_modules tag options
    • Project: Joomla!
    • SubProject: CMS
    • Impact: Moderate
    • Severity: Low
    • Versions: 3.0.0-3.9.18
    • Exploit type: XSS
    • Reported Date: 2020-May-06
    • Fixed Date: 2020-June-02
    • CVE Number: CVE-2020-13762

    Description

    Incorrect input validation of the module tag option in com_modules allow XSS attacks.

    Affected Installs

    Joomla! CMS versions 3.0.0 - 3.9.18

    Solution

    Upgrade to version 3.9.19

    Contact

    The JSST at the Joomla! Security Centre.

    Reported By: Bui Duc Anh Khoa from Viettel Cyber Security


  • [20200602] - Core - Inconsistent default textfilter settings
    • Project: Joomla!
    • SubProject: CMS
    • Impact: Low
    • Severity: Low
    • Versions: 2.5.0-3.9.18
    • Exploit type: Insecure Permissions
    • Reported Date: 2020-April-23
    • Fixed Date: 2020-June-02
    • CVE Number: CVE-2020-13763

    Description

    The default settings of the global "textfilter" configuration doesn't block HTML inputs for 'Guest' users. With 3.9.19, the textfilter for new installations has been set to 'No HTML' for the groups 'Public', 'Guest' and 'Registered'.

    Affected Installs

    Joomla! CMS versions 2.5.0 - 3.9.18

    Solution

    Upgrade to version 3.9.19

    Contact

    The JSST at the Joomla! Security Centre.

    Reported By: Brian Teeman


  • [20200601] - Core - XSS in modules heading tag option
    • Project: Joomla!
    • SubProject: CMS
    • Impact: Moderate
    • Severity: Low
    • Versions: 3.0.0-3.9.18
    • Exploit type: XSS
    • Reported Date: 2020-May-06
    • Fixed Date: 2020-June-02
    • CVE Number: CVE-2020-13761

    Description

    Lack of input validation in the heading tag option of the "Articles – Newsflash" and "Articles - Categories" modules allow XSS attacks.

    Affected Installs

    Joomla! CMS versions 3.0.0 - 3.9.18

    Solution

    Upgrade to version 3.9.19

    Contact

    The JSST at the Joomla! Security Centre.

    Reported By: Bui Duc Anh Khoa from Viettel Cyber Security


隨機相片

dsc_0078-16.jpg

搜尋網站內容

User Menu

訪客計數

mod_vvisit_countermod_vvisit_countermod_vvisit_countermod_vvisit_countermod_vvisit_countermod_vvisit_countermod_vvisit_counter
mod_vvisit_counter今日10
mod_vvisit_counter昨日147
mod_vvisit_counter本週791
mod_vvisit_counter本月1423
mod_vvisit_counter總計100717

Phoca Gallery Image Module