An issue was discovered in Joomla! before 3.9.4. The JSON handler in com_config lacks input validation, leading to XSS.
https://euvd.enisa.europa.eu/vulnerability/EUVD-2019-19077
https://developer.joomla.org/security-centre/772-20190301-core-xss-in-com-config-json-handler