CVE-2023-39971

Improper Neutralization of Input During Web Page Generation vulnerability in AcyMailing Enterprise component for Joomla allows XSS. This issue affects AcyMailing Enterprise component for Joomla: 6.7.0-8.6.3.
Configurations

Configuration 1 (hide)

cpe:2.3:a:acymailing:acymailing:*:*:*:*:enterprise:joomla\!:*:*

History

02 Dec 2023, 01:15

Type Values Removed Values Added
Summary Improper Neutralization of Input During Web Page Generation vulnerability in AcyMailing Enterprise component for Joomla allows XSS. This issue affects AcyMailing Enterprise component for Joomla: 6.7.0-8.6.3. Improper Neutralization of Input During Web Page Generation vulnerability in AcyMailing Enterprise component for Joomla allows XSS. This issue affects AcyMailing Enterprise component for Joomla: 6.7.0-8.6.3.

24 Aug 2023, 18:03

Type Values Removed Values Added
References (MISC) https://www.acymailing.com/acymailing-release-security-%F0%9F%94%90-news-updates/ - (MISC) https://www.acymailing.com/acymailing-release-security-%F0%9F%94%90-news-updates/ - Release Notes, Vendor Advisory
References (MISC) https://extensions.joomla.org/extension/acymailing-starter/ - (MISC) https://extensions.joomla.org/extension/acymailing-starter/ - Product
CWE CWE-79
First Time Acymailing
Acymailing acymailing
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 6.1
CPE cpe:2.3:a:acymailing:acymailing:*:*:*:*:enterprise:joomla\!:*:*

17 Aug 2023, 21:15

Type Values Removed Values Added
New CVE

Information

Published : 2023-08-17 21:15

Updated : 2024-02-28 20:33


NVD link : CVE-2023-39971

Mitre link : CVE-2023-39971

CVE.ORG link : CVE-2023-39971


JSON object : View

Products Affected

acymailing

  • acymailing
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')