Impact
The vulnerability arises from a lack of escaping in the modalreturn layouts of several Joomla components, allowing attackers to run in the visitor’s browser. The weakness is classified as CWE‑79.
Affected Systems
The issue affects the Joomla! CMS supplied by the Joomla! Project. Specific version numbers are not provided in the advisory, so any installation that has not yet applied recent updates could be vulnerable.
Risk and Exploitability
The CVSS score of 5.9 reflects moderate risk, while the EPSS score of < 1% indicates a very low likelihood of exploitation and the vulnerability is not listed in the KEV catalog. The likely attack vector is through web interaction with the affected modalreturn layout, where an attacker can supply crafted input to trigger the XSS. Although the exploitation requires that users load the vulnerable interface, remote exploitation is possible if the site exposes the modalreturn functionality to unauthenticated or authenticated users.
OpenCVE Enrichment