CVE-2018-6378
In Joomla! Core before 3.8.8, inadequate filtering of file and folder names leads to various XSS attack vectors in the media manager.
MEDIUM
Joomla CMS
Description
In Joomla! Core before 3.8.8, inadequate filtering of file and folder names leads to various XSS attack vectors in the media manager.
Sévérité
6.1
Moyenne · CVSS 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Score retenu : NVD
| Source | Sévérité d'origine | CVSS |
|---|---|---|
| NVD | MEDIUM | 6.1 (v3.0) |
Produit et versions
- Produit
- Joomla CMS
- Corrigée dans
- 3.8.8
- Publiée
- 22/05/2018
- Modifiée
- 17/06/2026
- CWE
- CWE-79
Versions concernées
- jusqu'à 3.8.8 (exclue)
Sources
- NVD CVE-2018-6378 vu
Ces informations proviennent des sources ci-dessus ; CVE Oyer n'y ajoute aucune interprétation.
Historique
- Détectée via nvd26/09/2026 09:34 UTC