A flaw in JRequest exists where variables set with JRequest::setVar are not cleaned when fetching the variable at a later point in the request. This can result in variable injection (unwanted characters injected into returned data).
Part of security release: 1.5.7
This vulnerability affects the following application versions:
- Joomla 1.5.0
- Joomla 1.5.1
- Joomla 1.5.2
- Joomla 1.5.3
- Joomla 1.5.4
- Joomla 1.5.5
- Joomla 1.5.6