Joomla! 3.4.x < 3.4.4 Login Module XSS
Medium Nessus Plugin ID 86020
SynopsisThe remote web server contains a PHP application that is affected by a cross-site scripting vulnerability.
DescriptionAccording to its self-reported version number, the Joomla! installation running on the remote web server is 3.4.x prior to 3.4.4.
It is, therefore, affected a cross-site (XSS) scripting vulnerability in the login module due to improper validation of user-supplied input.
An unauthenticated, remote attacker can exploit this to execute arbitrary script code in a user's browser session.
Note that Nessus has not tested for this issue but has instead relied only on the application's self-reported version number.
SolutionUpgrade to Joomla! version 3.4.4 or later.