Description
In Joomla! 3.2.0 through 3.6.5 (fixed in 3.7.0), inadequate escaping of file and folder names leads to XSS vulnerabilities in the template manager component.
Remediation
References
Related Vulnerabilities
Drupal Core 8.5.0 Remote Code Execution (8.5.0)
OpenSSL Resource Management Errors Vulnerability (CVE-2009-4355)
WordPress Plugin Age Verify Cross-Site Scripting (0.2.8)
WordPress Plugin Parsian Bank Woocommerce Cross-Site Scripting (1.0)
WordPress Plugin TweetScribe Cross-Site Request Forgery (1.1)