LiveActive security incident?Get immediate response
CVE Record

CVE-2021-23124: [20210102] - Core - XSS in mod_breadcrumbs aria-label attribute

An issue was discovered in Joomla! 3.9.0 through 3.9.23. The lack of escaping in mod_breadcrumbs aria-label attribute allows XSS attacks.

UnknownCVSS not scoredNot KEV-listedUpdated
Glexia's TakeAutomated analysisunknown

Security readout for executives and security teams

Plain-English summary

CVE-2021-23124 is a cross-site scripting issue in Joomla! CMS breadcrumbs. Affected sites running Joomla! 3.9.0 through 3.9.23 may allow script injection through an unescaped aria-label attribute in mod_breadcrumbs. The sources do not provide CVSS, exploit prerequisites, or confirmed exploitation.

Executive priority

Treat this as a targeted web application risk, especially for internet-facing Joomla sites. Prioritize identifying affected versions and following Joomla guidance, but avoid emergency language unless local exposure or exploit evidence is confirmed.

Technical view

The vulnerability is caused by missing escaping in the mod_breadcrumbs aria-label attribute in Joomla! CMS 3.9.0-3.9.23. The documented impact is XSS. The source bundle does not identify CWE, attack complexity, authentication requirements, exploit type, or a specific fixed version.

Likely exposure

Exposure is limited to Joomla! CMS installations running versions 3.9.0 through 3.9.23 with the breadcrumbs module present or enabled. The bundle does not state whether configuration, permissions, or user interaction are required.

Exploitation context

The bundle and KEV flag do not support active exploitation. Public evidence here only says the escaping flaw allows XSS attacks; it does not confirm exploited-in-the-wild activity or provide exploit maturity details.

Researcher notes

Evidence is sparse: no CVSS, CWE, patch version, exploit conditions, or attack vector details are included. Analysis should stay anchored to the affected range, component, and XSS class until the Joomla advisory is reviewed directly.

Mitigation direction

  • Inventory Joomla! CMS versions across public and internal sites.
  • Flag Joomla! 3.9.0 through 3.9.23 as affected.
  • Review the Joomla vendor advisory for the supported fix or mitigation.
  • Apply vendor-supported updates through normal change control.
  • Retest affected pages after remediation.

Validation and detection

  • Confirm the running Joomla! CMS version on each site.
  • Check whether mod_breadcrumbs is used on exposed pages.
  • Review page output for unsafe aria-label rendering in breadcrumbs.
  • Verify remediation against the Joomla vendor advisory.
  • Record unresolved instances for risk acceptance or upgrade planning.
Prepared
Confidence
medium
Sources
3

Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.

Potential ATT&CK relevance

Conservative CVE-to-ATT&CK context

These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.

ATT&CK lookup starting points

Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.

cve · low confidence lookup

CVE-2021-23124 mapping review

Open the CVE-to-ATT&CK bridge for reviewed, inferred, or future official mappings tied to this CVE.

Open ATT&CK lookup
Vulnerability profileCVE Program record
Severity
Unknown
CVSS
Not scored
Known Exploited
No
Published
Official CVE source material

CNA and ADP enrichment extracted from CVE v5

These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.

0CVSS vectors
0Timeline events
0ADP providers
2Source links

CVSS and timeline data

No CVSS vectors or timeline events were available in the normalized CVE source material.

Affected products

Products and packages named in the record

VendorProductVersion / packageStatus
Joomla! ProjectJoomla! CMS3.9.0-3.9.23Listed
Weakness

CWE details

No CWE listed

CWE links open Glexia weakness intelligence pages with official CWE context, developer remediation guidance, and related CVE mappings.