CVE-2023-39971

Improper Neutralization of Input During Web Page Generation vulnerability in AcyMailing Enterprise component for Joomla allows XSS. This issue affects AcyMailing Enterprise component for Joomla: 6.7.0-8.6.3.
Configurations

Configuration 1 (hide)

cpe:2.3:a:acymailing:acymailing:*:*:*:*:enterprise:joomla\!:*:*

History

02 Dec 2023, 01:15

Type Values Removed Values Added
Summary Improper Neutralization of Input During Web Page Generation vulnerability in AcyMailing Enterprise component for Joomla allows XSS. This issue affects AcyMailing Enterprise component for Joomla: 6.7.0-8.6.3. Improper Neutralization of Input During Web Page Generation vulnerability in AcyMailing Enterprise component for Joomla allows XSS. This issue affects AcyMailing Enterprise component for Joomla: 6.7.0-8.6.3.

24 Aug 2023, 18:03

Type Values Removed Values Added
References (MISC) https://www.acymailing.com/acymailing-release-security-%F0%9F%94%90-news-updates/ - (MISC) https://www.acymailing.com/acymailing-release-security-%F0%9F%94%90-news-updates/ - Release Notes, Vendor Advisory
References (MISC) https://extensions.joomla.org/extension/acymailing-starter/ - (MISC) https://extensions.joomla.org/extension/acymailing-starter/ - Product
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 6.1
First Time Acymailing acymailing
Acymailing
CWE CWE-79
CPE cpe:2.3:a:acymailing:acymailing:*:*:*:*:enterprise:joomla\!:*:*

17 Aug 2023, 21:15

Type Values Removed Values Added
New CVE

Information

Published : 2023-08-17 21:15

Updated : 2023-12-10 15:14


NVD link : CVE-2023-39971

Mitre link : CVE-2023-39971

CVE.ORG link : CVE-2023-39971


JSON object : View

Products Affected

acymailing

  • acymailing
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')