Description
In Joomla! Core before 3.8.8, inadequate filtering of file and folder names leads to various XSS attack vectors in the media manager.
Remediation
References
Related Vulnerabilities
Drupal Core 9.1.x Cross-Site Scripting (9.1.0 - 9.1.13)
phpMyFAQ Improper Access Control Vulnerability (CVE-2023-1883)
Moodle Improper Access Control Vulnerability (CVE-2020-25629)
Joomla! Core Information Disclosure (1.5.0 - 3.7.5)
Moodle Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2012-0799)