Description
In Joomla! 3.2.0 through 3.6.5 (fixed in 3.7.0), inadequate escaping of file and folder names leads to XSS vulnerabilities in the template manager component.
Remediation
References
Related Vulnerabilities
WordPress Plugin Jigoshop Multiple Unspecified Vulnerabilities (1.17.13)
MySQL CVE-2019-2481 Vulnerability (CVE-2019-2481)
Atlassian Jira CVE-2021-43947 Vulnerability (CVE-2021-43947)
WordPress Plugin Photo Gallery by 10Web-Mobile-Friendly Image Gallery Cross-Site Scripting (1.5.68)
MySQL Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2020-2922)