Impact
An improper validation of user inputs in the Phoca Guestbook extension for Joomla allows an attacker to inject malicious script that is reflected back to the victim's browser. Successful exploitation can execute arbitrary JavaScript in the context of the guestbook page, giving the attacker the ability to steal authentication cookies, perform defacement, redirect users, or otherwise compromise user sessions.
Affected Systems
The affected component is the Phoca Guestbook extension from phoca.cz, with versions ranging from 5.0.0 through 6.1.0. Any Joomla installation that includes these releases is vulnerable; the issue is tied to the guestbook input handling.
Risk and Exploitability
The CVSS score of 5.1 indicates a moderate risk profile, while an EPSS score of less than 1% suggests a low likelihood of widespread exploitation at present. The vulnerability is not listed in the CISA KEV catalog, so no known widespread attacks have been reported. Attackers do not require elevated privileges; the attack vector is likely a crafted URL or input that an unsuspecting user clicks or submits. The reflected nature means the injected script runs in the victim’s browser, potentially enabling cookie theft or session hijacking.
OpenCVE Enrichment