Description
An issue was discovered in Joomla! 3.1.0 through 3.9.23. The lack of escaping of image-related parameters in multiple com_tags views cause lead to XSS attack vectors.
Remediation
References
Related Vulnerabilities
concrete5 Unrestricted Upload of File with Dangerous Type Vulnerability (CVE-2020-24986)
ownCloud Improper Authentication Vulnerability (CVE-2014-9043)
WordPress 6.4.x Multiple Vulnerabilities (6.4 - 6.4.4)
WordPress Plugin WP Business Intelligence Lite SQL Injection (1.6.1)
WordPress Plugin Visualizer:Tables and Charts Manager for WordPress Cross-Site Scripting (3.9.4)