Alert GCSA-26242 - Aggiornamento di sicurezza per Joomla!

-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 ****************************************************************** alert ID: GCSA-26242 data: 30 settembre 2026 titolo: Aggiornamento di sicurezza per Joomla! ****************************************************************** :: Descrizione del problema Sono state rilasciate nuova versioni del CMS Joomla! con le quali vengono corrette 16 vulnerabilita', delle quali 5 hanno un livello di impatto "alto". [20260901] - Core - XSS in HTMLHelper::link method [20260902] - Core - Unauthorized user account creation via profile.save controller [20260903] - Core - Improper ACL checks for access level webservice endpoints [20260904] - Core - XSS in the generic media output layouts [20260905] - Core - Arbitrary directory deletion via cache purge action [20260906] - Core - Improper ACL checks in content history comparison view [20260907] - Core - Improper ACL checks in outputs for tagged items [20260908] - Core - XSS in HTML Mail Templates [20260911] - Core - XSS in link toolbar layout [20260909] - Core - SSRF vectors in various core extensions [20260910] - Core - Improper ACL checks for workflow stage changes [20260912] - Core - XSS in module list [20260913] - Core - Improper ACL checks for varous webservice edit tasks [20260914] - Core - MFA Authentication Bypass through rememberme cookies [20260915] - Core - XSS filter bypass in InputFilter via HTML5 entity decode mismatch [20260916] - Core - XSS filter bypass in InputFilter via whitespace characters in HTML data URIs Maggiori dettagli sono disponibili alla sezione "Riferimenti". :: Software interessato Joomla! versioni dalla 1.5.0 alla 5.4.8 Joomla! versioni dalla 6.0.0 alla 6.1.3 :: Impatto Cross-site Scripting (XSS) Bypass delle funzionalita' di sicurezza (SFB) Attacco all'integrita' dei dati (Data Manipulation) Accesso a dati riservati (ID) :: Soluzioni Aggiornare alle versioni piu' recenti (5.4.9, 6.1.4) https://downloads.joomla.org/cms https://downloads.joomla.org/latest https://downloads.joomla.org/cms/joomla5/5-4-9 https://downloads.joomla.org/cms/joomla6/6-1-4 :: Riferimenti Joomla! Release News https://www.joomla.org/announcements/release-news/joomla-6-1-4-5-4-9-security-bugfix-release.html Joomla! Security Announcements https://developer.joomla.org/security-centre/ Mitre CVE https://www.cve.org/CVERecord?id=CVE-2026-90906 https://www.cve.org/CVERecord?id=CVE-2026-90907 https://www.cve.org/CVERecord?id=CVE-2026-90913 https://www.cve.org/CVERecord?id=CVE-2026-90914 https://www.cve.org/CVERecord?id=CVE-2026-90915 https://www.cve.org/CVERecord?id=CVE-2026-90916 https://www.cve.org/CVERecord?id=CVE-2026-90917 https://www.cve.org/CVERecord?id=CVE-2026-90918 https://www.cve.org/CVERecord?id=CVE-2026-92224 https://www.cve.org/CVERecord?id=CVE-2026-92222 https://www.cve.org/CVERecord?id=CVE-2026-92223 https://www.cve.org/CVERecord?id=CVE-2026-92225 https://www.cve.org/CVERecord?id=CVE-2026-92226 https://www.cve.org/CVERecord?id=CVE-2026-92227 https://www.cve.org/CVERecord?id=CVE-2026-92231 https://www.cve.org/CVERecord?id=CVE-2026-92232 GARR CERT Security Alert - subscribe/unsubscribe: http://www.cert.garr.it/alert/ricevi-gli-alert-di-cert -----BEGIN PGP SIGNATURE----- iF0EAREIAB0WIQTGpdiR5MqstacBGHbBnEyTZRJgQgUCarz+sgAKCRDBnEyTZRJg QiPfAKDJPBMcjEmOqT9VV0vmoVyBKvbRKgCgqPOeXEUaFau744nS5JN+SgZbX5M= =za7Y -----END PGP SIGNATURE-----