Impact
This vulnerability allows an unauthenticated attacker to embed malicious script content that is stored by the Joomla extension 4Analytics and subsequently delivered to users who consume the AI analysis feature. The flaw arises from insufficient sanitization of input, permitting execution of arbitrary JavaScript in the victim’s browser, which can alter page content or exfiltrate data to a remote server. It is a classic stored XSS flaw (CWE‑79).
Affected Systems
All installations of the weeblr.com 4Analytics extension for Joomla whose bundled version is earlier than 5.0.2 are affected. Versions 5.0.2 and later contain the fix and are not vulnerable.
Risk and Exploitability
The CVSS assessment assigns a high severity score of 8.6, indicating significant potential for damage. The EPSS score of less than 1% suggests the probability of observed exploitation is currently very low, yet the issue remains high‑risk given its unauthenticated nature. Based on the description, it is inferred that the attack vector is an unauthenticated user submitting crafted input to the AI analysis feature; the malicious payload is stored by the extension and later executed for any user who loads the affected content.
OpenCVE Enrichment