Us   Eu   Au Get in touch

[20130404] - Core - XSS Vulnerability

  • Project: Joomla!
  • SubProject: All
  • Severity: Low
  • Versions: 2.5.9 and earlier 2.5.x versions. 3.0.3 and earlier 3.0.x versions.
  • Exploit type: XSS Vulnerability
  • Reported Date: 2013-February-15
  • Fixed Date: 2013-April-24
  • CVE Number: None


Use of old version of Flash-based file uploader leads to XSS vulnerability.

Affected Installs

Joomla! version 2.5.9 and earlier 2.5.x versions; and version 3.0.2 and earlier 3.0.x versions.


Upgrade to version 2.5.10,  3.1.0 or 3.0.4.


The JSST at the Joomla! Security Center.

Reported By: Reginaldo Silva
[20130404] - Core - XSS Vulnerability

Read more

Contact us

Need a Joomla Expert?