Description
An issue was discovered in Joomla! before 3.9.15. Inadequate escaping of usernames allows XSS attacks in com_actionlogs.
Remediation
References
Related Vulnerabilities
WordPress Plugin Smash Balloon Social Post Feed Cross-Site Scripting (4.1)
WordPress Plugin WP ULike Multiple Vulnerabilities (3.1)
WordPress Plugin Smart Manager for WooCommerce & WpeC Multiple Unspecified Vulnerabilities (3.9.13)
WordPress Plugin WPtouch 'wptouch_redirect' Parameter URI Redirection (1.9.32)