An issue was discovered in Joomla! through 3.9.19. Lack of input filtering and escaping allows XSS attacks in mod_random_image.
Source: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-15696
Reference (s):
- https://developer.joomla.org/security-centre/822-20200705-core-escape-mod-random-image-link.html

