Description
An issue was discovered in Joomla! 3.9.0 through 3.9.23. The lack of escaping in mod_breadcrumbs aria-label attribute allows XSS attacks.
Remediation
References
Related Vulnerabilities
Oracle JRE CVE-2024-21217 Vulnerability (CVE-2024-21217)
WordPress Plugin QR Redirector Security Bypass (1.5)
WordPress Plugin FAQ Multiple Cross-Site Scripting Vulnerabilities (1.0.14)
Oracle JRE CVE-2014-0451 Vulnerability (CVE-2014-0451)
WordPress Plugin JobSearch WP Job Board Cross-Site Scripting (1.5.4)