RULE(RULE ID:321873)

Rule General Information
Release Date: 2019-06-20
Rule Name: Joomla! com_fields Cross-Site Scripting (XSS) Vulnerability (CVE-2018-6377)
Severity:
CVE ID:
Rule Protection Details
Description: In Joomla! before 3.8.4, inadequate input filtering in com_fields leads to an XSS vulnerability in multiple field types, i.e., list, radio, and checkbox
Impact: An attacker can conduct a cross-site scripting attack to inject malicious client-side scripts into web pages viewed by other users, or to bypass access controls such as the same-origin policy, if affected version is installed.
Affected OS: Windows, Linux, FreeBSD, Solaris, Other Unix, Network Device, Mac OS, iOS, Android, Others
Reference: SecurityFocusBID:102917
SecurityTrackerID:1040316
https://developer.joomla.org/security-centre/720-20180103-core-xss-vulnerability.html
Solutions
The vendors have released upgrade patches to fix vulnerabilities, please visit:
https://developer.joomla.org/security-centre/720-20180103-core-xss-vulnerability.html