CVE-2024-40743

CVE-2024-40743: [20240805] - Core - XSS vectors in Outputfilter::strip* methods

Vendor Joomla! Project
Product Joomla! CMS
Weakness CWE-79 · XSS
Published August 20, 2024
Last update November 3, 2024

CVSS base score

What the vulnerability does

01Description

The stripImages and stripIframes methods didn't properly process inputs, leading to XSS vectors.

Key dates

02Disclosure timeline

August 20, 2024 CVE published
November 3, 2024 Record updated