(#Several vulnerabilities were reported in Joomla third-party modules:#- K2: cross-site scripting. This vulnerability is located in the administration panel#- VideoFlow: SQL injection in the "searchword" parameter.##Proofs of concept are available.)
Vulnerable Products
Vulnerable Software: Joomla (OSM Development Team) -
Solution
Versions 2.7.1 of K2 fixes the vulnerability affecting it.