VYPR
Medium severity6.1NVD Advisory· Published Jul 10, 2022· Updated Jun 17, 2026

CVE-2022-27910

CVE-2022-27910

Description

In Joomla component 'Joomlatools - DOCman 3.5.13 (and likely most versions below)' are affected to an reflected Cross-Site Scripting (XSS) in an image upload function

Affected products

4
  • Joomlatools/DOCmanllm-create3 versions
    <=3.5.13+ 2 more
    • (no CPE)range: <=3.5.13
    • cpe:2.3:a:joomlatools:docman:*:*:*:*:*:joomla\!:*:*range: <3.5.14
    • (no CPE)range: <=3.5.13
  • Joomla/DOCmanllm-create
    Range: <=3.5.13

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.