Impact
The vulnerability is a lack of escaping that allows an attacker to inject arbitrary JavaScript into the update list view of the com_installer component, exposing the site to a cross‑site scripting (CWE‑79) flaw. The injection enables execution of scripts in the browsers of users who view the vulnerable page and does not compromise server‑side resources. The CVSS score of 5.9 indicates moderate severity, and the EPSS score of less than 1% reflects a low exploitation likelihood. The vulnerability is not listed in CISA's KEV catalog, suggesting limited public exploitation. The likely attack vector is through the web interface; exploitation requires access to the update list view and results in client‑side script execution.
Affected Systems
Joomla! CMS from the Joomla! Project is affected. No specific version numbers are provided in the data, so the issue may exist in the update list view at the time of the advisory.
Risk and Exploitability
The CVSS score of 5.9 indicates a moderate level of severity, while the EPSS of less than 1% shows that the vulnerability is unlikely to be actively exploited in the wild. The lack of listing in CISA's KEV catalog also points to limited public exploitation. Given that the flaw exists in the update list view of the com_installer component, the most plausible attack vector is through the Joomla! web interface; an attacker would need to access that page to inject arbitrary JavaScript, resulting in client‑side script execution for users who view the page.
OpenCVE Enrichment