CVE-2019-14654
Last modified
CVE-2019-14654 is a vulnerability of currently unknown severity. In Joomla! 3.9.7 and 3.9.8, inadequate filtering allows users authorised to create custom fields to manipulate the filtering options and inject an unvalidated option. In other words, the filter attribute in subform fields allows remote code execution. EPSS estimates a 2.31% chance of exploitation in the next 30 days.
Description
In Joomla! 3.9.7 and 3.9.8, inadequate filtering allows users authorised to create custom fields to manipulate the filtering options and inject an unvalidated option. In other words, the filter attribute in subform fields allows remote code execution. This is fixed in 3.9.9.
Metrics
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Joomla | Joomla\! | 3.9.7 |
| Joomla | Joomla\! | 3.9.8 |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2019-14654?
How severe is CVE-2019-14654?
How do I fix CVE-2019-14654?
Are you affected by CVE-2019-14654?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
