Nixpkgs security tracker

Login with GitHub
⚠️ You are using a production deployment that is still only suitable for demo purposes. Any work done in this might be wiped later without notice.

Suggestion detail

Dismissed
(no matching packages found)
created 1 month, 1 week ago Activity log
  • Created & dismissed (no matching packages found) suggestion
Joomla Extension - regularlabs.com - XSS vectors in tag-provided inputs in various Regular Labs extensions

Tag-provided custom HTML, module content/title overrides and decoded modal or tooltip values could execute unsafe markup. A content author could inject JavaScript that ran in visitors’ browsers.

References

Affected products

Modals extension for Joomla
  • ==1.0.0-15.0.0
Tooltips extension for Joomla
  • ==1.0.0-9.4.7
Users Anywhere Pro extension for Joomla
  • ==1.0.0-1.2.7
Modules Anywhere Pro extension for Joomla
  • ==1.0.0-8.4.1
Articles Anywhere Pro extension for Joomla
  • ==1.0.0-18.0.2