Impact
The Joomla! CMS suffers an input validation flaw in the Multifactor Authentication (MFA) management views that allows arbitrary script injection. When a user—typically an administrator—loads the MFA interface, the injected code executes in the victim’s browser, which can modify page content or collect information from the session context. This flaw is a classic Cross‑Site Scripting weakness listed as CWE‑79.
Affected Systems
The Joomla! Project’s Joomla! CMS product is affected, specifically the MFA method management functionality. No explicit version or release information is provided, meaning that any Joomla! CMS installation that includes the MFA management feature could be vulnerable. Site administrators should assess if their installation contains that capability.
Risk and Exploitability
The CVSS score of 5.9 denotes moderate severity. With an EPSS score of less than 1% and no listing in the CISA KEV catalog, the likelihood of active exploitation is currently low. The attack vector appears to be a user who can access the MFA management interface, which typically requires administrative privileges. Because the description does not state whether remote exploitation is possible without authentication, the risk is judged to remain moderate pending further evidence.
OpenCVE Enrichment