← Back to CVE List

CVE-2018-7717

Published: 2018-03-05T23:29Z
Last Modified: 2024-11-21T04:12Z
Source: MITRE CVE List
License: MITRE-CVE-TOS
The htmlImageAddTitleAttribute function in sige.php in the Kubik-Rubik Simple Image Gallery Extended (SIGE) extension 3.2.3 for Joomla! has XSS via a crafted image header, as demonstrated by the Caption-Abstract header object in a JPEG file. This is fixed in 3.3.1. > MITRE Terms of Use apply – see LICENSE‑MITRE.txt