Joomla! JSE Event Component "info" Mini Calendar Cross-Site Scripting Vulnerability

SECUNIA ADVISORY ID:
SA54421

VERIFY ADVISORY:
Secunia.com
http://secunia.com/advisories/54421/
Customer Area (Credentials Required)
https://ca.secunia.com/?page=viewadvisory&vuln_id=54421

RELEASE DATE:
2013-08-13
DESCRIPTION:
Gaston Traberg has reported a vulnerability in the JSE Event
component for Joomla!, which can be exploited by malicious people to
conduct cross-site scripting attacks.

Input passed to the "info" parameter in
modules/mod_jse_mini_calendar/tmpl/tootip.php is not properly
sanitised before being returned to the user. This can be exploited to
execute arbitrary HTML and script code in a user's browser session in
context of an affected site.

The vulnerability is reported in versions prior to 1.0.1.

SOLUTION:
Update to version 1.0.1.

PROVIDED AND/OR DISCOVERED BY:
Gaston Traberg

ORIGINAL ADVISORY:
Joomseller:
http://joomseller.com/joomla-components/jse-event.html

RECENT ARTICLE

RECENT POST