Description
In Joomla! 3.x before 3.9.12, inadequate escaping allowed XSS attacks using the logo parameter of the default templates.
Remediation
References
Related Vulnerabilities
Oracle Database Server CVE-2021-2175 Vulnerability (CVE-2021-2175)
Jenkins 7PK - Security Features Vulnerability (CVE-2014-9634)
WordPress Plugin Formidable-Clockwork SMS Cross-Site Scripting (1.0.3)
WordPress Plugin Time Sheets Multiple Cross-Site Scripting Vulnerabilities (1.5.1)
WordPress Deserialization of Untrusted Data Vulnerability (CVE-2020-36326)