'Joomla 3.10.x SQL Injection XSS Vulnerability

I have a website setup on my infrastructure that is running Joomla 3.10.8. During a security audit, certain SQL injection vulnerabilities / XSS have been identified.

The setup includes a bunch of plugins like K2 for managing the display of content and workflows. As there has been no custom development of any of these components, how do I address this security issue?

Are there any recommendations or best practices that I can follow?



Solution 1:[1]

If the vulnerability is indeed in core Joomla and not in one of the installed extensions you can contact the Joomla Security Strike Team via this page https://developer.joomla.org/security.html

Sources

This article follows the attribution requirements of Stack Overflow and is licensed under CC BY-SA 3.0.

Source: Stack Overflow

Solution Source
Solution 1 hvdmeer