Joomla Frei-Chat Component One Script Insertion Vulnerability

SECUNIA ADVISORY ID:
SA40751

VERIFY ADVISORY:
Secunia.com
http://secunia.com/advisories/40751/
Customer Area (Credentials Required)
https://ca.secunia.com/?page=viewadvisory&vuln_id=40751

RELEASE DATE:
2010-07-26

DESCRIPTION:
nag_sunny has reported a vulnerability in the Frei-Chat component for
Joomla, which can be exploited by malicious people to conduct script
insertion attacks.

Certain unspecified input is not properly sanitised before being
displayed to the user. This can be exploited to insert arbitrary HTML
and script code, which will be executed in a user's browser session in
context of an affected site when the malicious data is being viewed.

The vulnerability is reported in versions prior to 2.1.2.

SOLUTION:
Update to version 2.1.2.

PROVIDED AND/OR DISCOVERED BY:
nag_sunny