The Joomla extension JMedia is vulnerable to a stored XSS vulnerability. Unsanitised SVG uploads served without nosniff, leading to stored/reflected XSS.
The Joomla extension JMedia is vulnerable to a stored XSS vulnerability. Unsanitised SVG uploads served without nosniff, leading to stored/reflected XSS.
Why this VPI (explainable, experimental)
VPI breakdown
| Impact | 94.00 |
| Exploitation signal(No additional exploitation signal) | ×1.00 |
| VPI | 94.00 |
VPI formula vpi-v1