1.6.4 security alert for layout override files
From Joomla! Documentation
This page is a candidate for deletion. The given reason is: This page is orphaned and the information is no longer current.
Last edit by Jennymac (talk · contrib) · Last edited on Sat, 17 Oct 2020 02:05:17 +0000
In version 1.6.4 a security fix was made to a number of layout files, specifically those for category lists for articles, weblinks, newsfeeds and contacts and the featured contact list. If you are using layout overrides for these you should ensure that you make the same changes are made in your template (if the same issue is present). Overrides are found in the html folder of your template. You may also wish to check layout files for extensions for the same issue since the core layouts are sometimes used as models.
The change made is to replace JfilterOutput::ampReplace with htmlspecialchars. The following files should be changed:
This change should also be made to the override found in the beez5 template