Description
In Joomla! before 3.9.19, lack of input validation in the heading tag option of the "Articles - Newsflash" and "Articles - Categories" modules allows XSS.
Remediation
References
Related Vulnerabilities
Envoy Proxy Reachable Assertion Vulnerability (CVE-2021-29258)
Chamilo Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2021-32925)
WordPress Plugin WPFront Scroll Top Cross-Site Scripting (2.0.5.07184)
WordPress Plugin Easy Testimonials Cross-Site Scripting (3.0.4)
WordPress Plugin ZTR Zeumic Work Timer Multiple Unspecified Vulnerabilities (1.0.6)