CVE-2011-4909

Vulnérabilités

CVE-2011-4909

Multiple cross-site scripting (XSS) vulnerabilities in Joomla!

MEDIUM Joomla CMS

Multiple cross-site scripting (XSS) vulnerabilities in Joomla! before 1.5.12 allow remote attackers to inject arbitrary web script or HTML via the HTTP_REFERER header to (1) components/com_content/views/article/tmpl/form.php, (2) components/com_user/controller.php, (3) plugins/system/legacy/html.php, or (4) templates/beez/html/com_content/article/form.php.

4.3 Moyenne · CVSS 2.0

AV:N/AC:M/Au:N/C:N/I:P/A:N

Score retenu : NVD

SourceSévérité d'origineCVSS
NVDMEDIUM 4.3 (v2.0)
Produit
Joomla CMS
Corrigée dans
Non précisée
Publiée
07/10/2012
Modifiée
16/06/2026
CWE
CWE-79
  • jusqu'à 1.5.11
  • 1.5.0 – 1.5.0
  • 1.5.1 – 1.5.1
  • 1.5.2 – 1.5.2
  • 1.5.3 – 1.5.3
  • 1.5.4 – 1.5.4
  • 1.5.5 – 1.5.5
  • 1.5.6 – 1.5.6
  • 1.5.7 – 1.5.7
  • 1.5.8 – 1.5.8
  • 1.5.9 – 1.5.9
  • 1.5.10 – 1.5.10

Ces informations proviennent des sources ci-dessus ; CVE Oyer n'y ajoute aucune interprétation.

  1. Détectée via nvd26/09/2026 09:34 UTC