Lack of escaping in mod_breadcrumbs aria-label attribute allowed XSS attacks.
CVE-2021-23124
This vulnerability affects the following application versions:
- Joomla 3.9.3
- Joomla 3.9.4
- Joomla 3.9.5
- Joomla 3.9.6
- Joomla 3.9.7
- Joomla 3.9.8
- Joomla 3.9.9
- Joomla 3.9.10
- Joomla 3.9.11
- Joomla 3.9.12
- Joomla 3.9.13
- Joomla 3.9.14
- Joomla 3.9.15
- Joomla 3.9.16
- Joomla 3.9.17
- Joomla 3.9.18
- Joomla 3.9.19
- Joomla 3.9.20
- Joomla 3.9.21
- Joomla 3.9.22
- Joomla 3.9.23