Impact
The weeblr.com 4Analytics extension for Joomla has an unauthenticated stored cross‑site scripting flaw that stems from an uncontrolled input field. The attacker can submit a crafted request that stores malicious JavaScript, which is later rendered to visitors without proper escaping. According to the updated description, the flaw may lead to website takeover in certain circumstances, allowing the attacker to hijack user sessions, deface the site, or execute arbitrary code in the context of the website.
Affected Systems
The vulnerability affects the weeblr.com 4Analytics extension for Joomla versions earlier than 5.0.2. All installations running those versions are impacted, regardless of site size or traffic.
Risk and Exploitability
With a CVSS score of 8.7 the flaw is considered high severity, but the EPSS score of less than 1% indicates a low current exploitation probability. The flaw is not listed in CISA's KEV catalog. Attackers can exploit it by sending a crafted, unauthenticated request that stores malicious payloads in the extension, which are then executed when the site is accessed by any user.
OpenCVE Enrichment