CVE-2020-15696
https://notcve.org/view.php?id=CVE-2020-15696
An issue was discovered in Joomla! through 3.9.19. Lack of input filtering and escaping allows XSS attacks in mod_random_image. Se detectó un problema en Joomla! versiones hasta el 3.9.19. • https://developer.joomla.org/security-centre/822-20200705-core-escape-mod-random-image-link.html • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •
CVE-2020-15695
https://notcve.org/view.php?id=CVE-2020-15695
An issue was discovered in Joomla! through 3.9.19. A missing token check in the remove request section of com_privacy causes a CSRF vulnerability. Se detectó un problema en Joomla! versiones hasta el 3.9.19. • https://developer.joomla.org/security-centre/820-20200703-core-csrf-in-com-privacy-remove-request-feature.html • CWE-352: Cross-Site Request Forgery (CSRF) •
CVE-2020-13760
https://notcve.org/view.php?id=CVE-2020-13760
In Joomla! before 3.9.19, missing token checks in com_postinstall lead to CSRF. En Joomla! versiones anteriores a 3.9.19, la falta de comprobaciones de token en com_postinstall conlleva a un ataque de tipo CSRF. • https://developer.joomla.org/security-centre/817-20200605-core-csrf-in-com-postinstall • CWE-352: Cross-Site Request Forgery (CSRF) •
CVE-2020-13761
https://notcve.org/view.php?id=CVE-2020-13761
In Joomla! before 3.9.19, lack of input validation in the heading tag option of the "Articles - Newsflash" and "Articles - Categories" modules allows XSS. En Joomla! versiones anteriores a 3.9.19, la falta de comprobación de entrada en la opción heading tag de los módulos "Articles - Newsflash" y "Articles - Categories" permite un ataque de tipo XSS. • https://developer.joomla.org/security-centre/813-20200601-core-xss-in-modules-heading-tag-option • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •
CVE-2020-13762
https://notcve.org/view.php?id=CVE-2020-13762
In Joomla! before 3.9.19, incorrect input validation of the module tag option in com_modules allows XSS. En Joomla! versiones anteriores a 3.9.19, una comprobación de entrada incorrecta de la opción module tag en com_modules permite un ataque de tipo XSS. • https://developer.joomla.org/security-centre/815-20200603-core-xss-in-com-modules-tag-options • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •