Reflected Cross-Site Scripting Vulnerability in Fabrik for Joomla!
CVE-2018-10727

6.1MEDIUM

Key Information:

Vendor

Fabrikar

Status
Vendor
CVE Published:
29 October 2019

What is CVE-2018-10727?

A reflected Cross-Site Scripting vulnerability exists in the fabrik_referrer hidden field within the Fabrik component for Joomla! versions up to v3.8.1. This flaw allows remote attackers to inject and execute arbitrary web scripts via the HTTP Referer header, potentially compromising the security of affected Joomla! applications. It is crucial for users to update and apply security measures to mitigate risks associated with this vulnerability.

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.