Description
In Joomla! 3.2.0 through 3.6.5 (fixed in 3.7.0), inadequate escaping of file and folder names leads to XSS vulnerabilities in the template manager component.
Remediation
References
Related Vulnerabilities
MySQL Numeric Errors Vulnerability (CVE-2006-3486)
Ampache Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2024-51484)
MySQL CVE-2020-2774 Vulnerability (CVE-2020-2774)
Drupal Improper Input Validation Vulnerability (CVE-2014-5019)
Tornado URL Redirection to Untrusted Site ('Open Redirect') Vulnerability (CVE-2023-28370)