What the vulnerability does
01Description
Joomla Extension - joomshopping.com - Reflective XSS in JoomShopping < 5.9.3 - The Joomla extension JoomShopping is vulnerable to an reflected XSS vulnerability in the product frontend controller.
CVSS base score
CVSS vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N
What the vulnerability does
Joomla Extension - joomshopping.com - Reflective XSS in JoomShopping < 5.9.3 - The Joomla extension JoomShopping is vulnerable to an reflected XSS vulnerability in the product frontend controller.
Explanation of Vulnerability in Simple Terms
JoomShopping contains a cross-site scripting (XSS) vulnerability that allows attackers to inject malicious scripts into the site. An attacker can craft a malicious link or page that, when visited by a user, executes JavaScript in their browser. This can lead to session hijacking, credential theft, or defacement. The vulnerability requires user interaction to exploit.
What an attacker can do
Inject and execute malicious JavaScript in users' browsers via crafted links or pages.
Potential impact on your site
Visitors to your site could have their sessions hijacked, credentials stolen, or see malicious content injected into pages.
Conditions required to exploit
A user must visit an attacker-controlled or attacker-modified page containing the malicious payload.
Key dates
External resources
Related vulnerabilities