Description
An issue was discovered in Joomla! before 3.9.3. Inadequate parameter handling in JavaScript code (core.js writeDynaList) could lead to an XSS attack vector.
Remediation
References
Related Vulnerabilities
Squid Out-of-bounds Write Vulnerability (CVE-2019-12527)
WordPress Plugin Best Image Gallery & Responsive Photo Gallery-FooGallery Security Bypass (1.6.15)
WordPress Plugin StatPress Cross-Site Scripting (1.2.9.1)
WordPress Plugin easyping-website subscriptions done right PHP Object Injection (0.0.1)