Joomla! JCE Component 'index.php' Cross Site Scripting Vulnerability
31 May. 2012
Summary
The JCE component for Joomla! is prone to a vulnerability that lets attackers upload arbitrary files because the application fails to adequately sanitize user-supplied input.
An attacker may leverage this issue to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This can allow the attacker to steal cookie-based authentication credentials and to launch other attacks.
Vendor Status:
Joomla JCE had issued an update for this vulnerability