Description
An issue was discovered in Joomla! 3.9.0 through 3.9.23. The lack of escaping in mod_breadcrumbs aria-label attribute allows XSS attacks.
Remediation
References
Related Vulnerabilities
WordPress Plugin Attachment File Icons (AF Icons) Cross-Site Request Forgery (1.3)
WordPress Plugin WooCommerce Security Bypass (6.3.0)
WordPress Plugin Yandex.News Feed by Teplitsa Cross-Site Scripting (1.12.5)
WordPress Plugin ActiveCampaign-Forms, Site Tracking, Live Chat Unspecified Vulnerability (5.7)