Impact
Phoca Maps 5.0.0 through 6.0.4 contains a reflected cross‑site scripting flaw caused by improper validation of user supplied text. When an attacker crafts a URL or submits input that the extension inserts back into the response without adequate escaping, the browser will execute the embedded script in the context of the victim’s session. This can lead to theft of session cookies, defacement or the injection of further malicious payloads. The weakness is a classic CWE‑79 scenario.
Affected Systems
The vulnerability affects the Joomla extension "Phoca Maps" provided by phoca.cz, specifically all builds from 5.0.0 to 6.0.4. Users running any of these versions on a Joomla site are exposed.
Risk and Exploitability
The CVSS score of 5.1 indicates moderate severity. The EPSS score of less than 1% signals a low probability of exploitation in the wild, and the item is not listed in the CISA KEV catalog. The flaw is client‑side; an attacker can invoke it by luring a user to a malicious link or submitting a crafted form, and it does not require authentication. While the threat is moderate, the impact on user trust and potential credential compromise warrants swift action.
OpenCVE Enrichment