CVE-2025-32465 HIGH

CVE-2025-32465: Extension - rsjoomla.com - Stored XSS vulnerability in RSTickets! component 1.9.12 - 3.3.0 for Joomla

Vendor Rsjoomla.com
Product RSTickets! component for Joomla
Weakness CWE-79 · XSS
Published June 11, 2025
Last update June 12, 2025

CVSS base score

8.5/10
Attack vector Network
Attack complexity Low
Privileges required Low
User interaction
Confidentiality
Integrity

CVSS vector

CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/S:N/AU:N/RE:L/U:Clear

What the vulnerability does

01Description

A stored XSS vulnerability in RSTickets! component 1.9.12 - 3.3.0 for Joomla was discovered. It allows attackers to perform cross-site scripting (XSS) attacks via sending crafted payload.

Explanation of Vulnerability in Simple Terms

02Summary

RSTickets! for Joomla contains a cross-site scripting (XSS) vulnerability that allows authenticated users to inject malicious scripts. An attacker with low-level access can craft a request that, when viewed by another user, executes arbitrary JavaScript in their browser. This can lead to session hijacking, credential theft, or unauthorized actions performed on behalf of the victim.

What an attacker can do

03Attacker Capabilities

Inject and execute malicious JavaScript in other users' browsers to steal sessions or perform unauthorized actions.

Potential impact on your site

04Site Impact

Authenticated attackers can compromise other users' accounts or perform actions as those users within your Joomla site.

Conditions required to exploit

05Prerequisites

Attacker must have a low-privilege Joomla account and the victim must view a page containing the injected payload.

Key dates

06Disclosure timeline

June 11, 2025 CVE published
June 12, 2025 Record updated

Related vulnerabilities

08Related CVE