CVE-2019-7741

MEDIUM

Joomla! 2.5.0-3.9.2 - Stored Cross-Site Scripting in Global Configuration Help URL

Title source: llm
STIX 2.1

Description

An issue was discovered in Joomla! before 3.9.3. Inadequate checks at the Global Configuration helpurl settings allowed stored XSS.

Scores

CVSS v3 6.1
EPSS 0.0007
EPSS Percentile 21.2%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

Details

CWE
CWE-79
Status published
Products (1)
joomla/joomla\! 2.5.0 - 3.9.2
Published Feb 12, 2019
Tracked Since Feb 18, 2026