Beveiligingsadvies

CVE-2018-7717

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2018-03-05 23:00:00
Laatst bijgewerkt 2024-09-17 02:00:50
Toegewezen door mitre
CVSS-score geen score
Status PUBLISHED

Beschrijving

The htmlImageAddTitleAttribute function in sige.php in the Kubik-Rubik Simple Image Gallery Extended (SIGE) extension 3.2.3 for Joomla! has XSS via a crafted image header, as demonstrated by the Caption-Abstract header object in a JPEG file. This is fixed in 3.3.1.