Description
In Joomla! 3.x before 3.9.12, inadequate escaping allowed XSS attacks using the logo parameter of the default templates.
Remediation
References
Related Vulnerabilities
WordPress Plugin Ultimate TinyMCE 'swfupload.swf' Cross-Site Scripting (3.5)
Oracle JRE CVE-2018-2637 Vulnerability (CVE-2018-2637)
WordPress Plugin Agent Storm by StormRETS Multiple Cross-Site Scripting Vulnerabilities (1.1.35)
PHP Improper Restriction of XML External Entity Reference Vulnerability (CVE-2013-1824)