Description
An issue was discovered in Joomla! 3.9.0 through 3.9.23. The lack of escaping in mod_breadcrumbs aria-label attribute allows XSS attacks.
Remediation
References
Related Vulnerabilities
WordPress Plugin User Login Log Cross-Site Scripting (2.2.2)
Moodle Improper Input Validation Vulnerability (CVE-2011-4582)
WordPress Plugin MainWP Dashboard Unspecified Vulnerability (2.0.22)
WordPress 3.9.x Same Origin Method Execution (SOME) Vulnerability (3.9 - 3.9.11)
WordPress Plugin Popup by Supsystic Cross-Site Scripting (1.10.4)