Description
In Joomla! 3.x before 3.9.12, inadequate escaping allowed XSS attacks using the logo parameter of the default templates.
Remediation
References
Related Vulnerabilities
Squid NULL Pointer Dereference Vulnerability (CVE-2020-14058)
Jenkins Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2022-20612)
MediaWiki Improper Authentication Vulnerability (CVE-2021-36128)
Drupal Core 6.x Remote Code Execution (6.0 - 6.38)
WordPress Plugin CMS Tree Page View Cross-Site Request Forgery (1.2.4)