Impact
The vulnerability arises from the lack of output escaping in readmore links for the com_content component, which allows an attacker to inject JavaScript that will execute in the browsers of anyone who views the affected links. This can lead to unauthorized script execution, session hijacking, or defacement of the site. The weakness is an example of OWASP CWE‑79, affecting the confidentiality and integrity of the application user base.
Affected Systems
Joomla! CMS installations that use the com_content component are affected. No specific version information is provided, so any releases that include this component and have not yet applied the advisory should be considered at risk.
Risk and Exploitability
The CVSS score of 6.9 indicates moderate severity, with a typical exploitation requiring the attacker to supply or influence content that contains a malicious readmore URL. Since the EPSS score is not available, the likelihood of exploitation cannot be quantified. The vulnerability is not listed in CISA’s KEV catalog, suggesting no confirmed widespread exploitation as of the last update. An attacker with the ability to create or edit content could craft a readmore link that executes arbitrary JavaScript in the victim’s browser, potentially compromising credentials or redirecting traffic.
OpenCVE Enrichment