A stored XSS vulnerability in the RSDirectory! component 1.0.0-2.2.8 Joomla was discovered. The issue allows remote authenticated attackers to inject arbitrary web script or HTML via the review reply component.
Advisories
Source ID Title
EUVD EUVD EUVD-2025-21869 A stored XSS vulnerability in the RSDirectory! component 1.0.0-2.2.8 Joomla was discovered. The issue allows remote authenticated attackers to inject arbitrary web script or HTML via the review reply component.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

References
Link Providers
https://rsjoomla.com/ cve-icon cve-icon
History

Fri, 18 Jul 2025 12:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 18 Jul 2025 10:00:00 +0000

Type Values Removed Values Added
Description A stored XSS vulnerability in the RSDirectory! component 1.0.0-2.2.8 Joomla was discovered. The issue allows remote authenticated attackers to inject arbitrary web script or HTML via the review reply component.
Title Extension - rsjoomla.com - Stored XSS vulnerability in RSDirectory! component 1.16.3-1.17.7 for Joomla
Weaknesses CWE-79
References
Metrics cvssV4_0

{'score': 5.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: Joomla

Published:

Updated: 2025-07-20T08:53:01.792Z

Reserved: 2025-06-11T19:08:08.079Z

Link: CVE-2025-50058

cve-icon Vulnrichment

Updated: 2025-07-18T11:26:53.011Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-07-18T10:15:34.523

Modified: 2025-07-22T13:06:27.983

Link: CVE-2025-50058

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.