What the vulnerability does
01Description
Lack of output escaping leads to a XSS vector in the multilingual associations component.
CVSS base score
CVSS vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:P/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N/E:U
What the vulnerability does
Lack of output escaping leads to a XSS vector in the multilingual associations component.
Explanation of Vulnerability in Simple Terms
Joomla! CMS versions 4.0.0 through 5.4.3 contain a cross-site scripting (XSS) vulnerability that allows authenticated users with high privileges to inject malicious scripts. An attacker must have administrative-level access and trick a user into visiting a crafted page. The injected script executes in the victim's browser, potentially compromising their session or stealing sensitive data.
What an attacker can do
Inject and execute malicious JavaScript in a victim's browser session.
Potential impact on your site
Administrators could be compromised if tricked into visiting attacker-controlled pages, risking site takeover or data theft.
Conditions required to exploit
Attacker needs high-level admin access and victim must click a malicious link or visit a crafted page.
Key dates
External resources
Related vulnerabilities