OSV 1.4.0 · unreviewed · 修改于 2026-08-31 23:34
发布时间
2026-08-31 23:34
GitHub 审查时间
—
NVD 发布时间
2026-08-31 22:17
源文件
advisories/unreviewed/2026/08/GHSA-v6p2-jx9w-8967/GHSA-v6p2-jx9w-8967.json
Joomla Extension - joomshaper.com - Stored Cross-Site Scripting (XSS) in MegaMenu Layout Container & Embed Inputs in Helix Ultimate < 2.2.10 - Unsanitized column and item configuration values stored within the MegaMenu layout JSON were rendered without complete contextual escaping, allowing injection of malicious HTML/JS. Stricter sanitization and tag allowlists via InputFilter and htmlspecialchars were implemented.
该公告没有提供结构化的受影响软件包信息。