Impact
Joomla Extension 'Keyboard Shortcuts' by regularlabs.com allows configuration of shortcuts via administrative interface that accepts arbitrary inline JavaScript. An attacker who can edit shortcut entries can inject malicious script that will run in the browsers of users who view content protected by the extension. This leads to cross‑site scripting, enabling theft of session cookies, defacement, or other malicious client‑side actions.
Affected Systems
This vulnerability impacts the Keyboard Shortcuts extension for Joomla supplied by regularlabs.com; any installation of the extension that has not applied the latest patch removes the inline JavaScript storage vulnerability. No specific version numbers were listed, so all unpatched installations of the extension are potentially affected.
Risk and Exploitability
The CVSS score of 6.1 classifies the flaw as medium severity, and the EPSS score of less than 1 percent indicates a low likelihood of exploitation at the time of analysis. The vulnerability is not yet catalogued in CISA KEV, suggesting no current known public exploits. Exploitation requires access to the Joomla administrative backend or a content editor with shortcut editing rights; the extent of damage depends on the privileges of the attacker’s account and the breadth of user exposure to the injected script.
OpenCVE Enrichment