Vulnerability Description
Cross-site scripting (XSS) vulnerability in the administrator panel in the com_users core component for Joomla! 1.5.x through 1.5.10 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Joomla | Joomla | 1.5 |
Related Weaknesses (CWE)
References
- http://developer.joomla.org/security/news/295-20090601-core-comusers-xss.htmlPatchVendor Advisory
- http://osvdb.org/54869Patch
- http://secunia.com/advisories/35278Vendor Advisory
- http://www.joomla.org/announcements/release-news/5235-joomla-1511-security-relea
- http://www.securityfocus.com/bid/35189ExploitPatch
- http://www.vupen.com/english/advisories/2009/1497
- https://exchange.xforce.ibmcloud.com/vulnerabilities/50924
- http://developer.joomla.org/security/news/295-20090601-core-comusers-xss.htmlPatchVendor Advisory
- http://osvdb.org/54869Patch
- http://secunia.com/advisories/35278Vendor Advisory
- http://www.joomla.org/announcements/release-news/5235-joomla-1511-security-relea
- http://www.securityfocus.com/bid/35189ExploitPatch
- http://www.vupen.com/english/advisories/2009/1497
- https://exchange.xforce.ibmcloud.com/vulnerabilities/50924
FAQ
What is CVE-2009-1940?
CVE-2009-1940 is a vulnerability with a CVSS score of 4.3 (MEDIUM). Cross-site scripting (XSS) vulnerability in the administrator panel in the com_users core component for Joomla! 1.5.x through 1.5.10 allows remote attackers to inject arbitrary web script or HTML via ...
How severe is CVE-2009-1940?
CVE-2009-1940 has been rated MEDIUM with a CVSS base score of 4.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2009-1940?
Check the references section above for vendor advisories and patch information. Affected products include: Joomla Joomla.