Description
An issue was discovered in Joomla! 3.9.0 through 3.9.23. The lack of escaping in mod_breadcrumbs aria-label attribute allows XSS attacks.
Remediation
References
Related Vulnerabilities
WordPress Plugin Ultimate Maps by Supsystic SQL Injection (1.1.12)
Java Unspesificed Vulnerability (CVE-2019-2821)
WordPress Plugin WP-PostViews Cross-Site Request Forgery (1.62)
WordPress Plugin EDD Favorites Cross-Site Scripting (1.0.6)
WordPress Plugin Freetobook review widget Unspecified Vulnerability (1.0)