Description
An issue was discovered in Joomla! 3.9.0 through 3.9.23. The lack of escaping in mod_breadcrumbs aria-label attribute allows XSS attacks.
Remediation
References
Related Vulnerabilities
UAParser.js Inefficient Regular Expression Complexity Vulnerability (CVE-2022-25927)
WordPress Plugin Afterpay Gateway for WooCommerce Cross-Site Scripting (3.2.0)
jQuery Validation Other Vulnerability (CVE-2021-43306)
WordPress Plugin Import and export users and customers Multiple Vulnerabilities (1.9.4.6)