Impact
Improper validation of user inputs within the Phoca Commander Joomla extension enables a reflected cross‑site scripting flaw. The vulnerability occurs when unsanitized data supplied by the user is reflected back in the page, allowing an attacker to inject arbitrary JavaScript that executes in the context of the victim’s browser. This could enable attackers to deface the site, harvest credentials, or perform social engineering tactics.
Affected Systems
The flaw affects Joomla sites that use the Phoca Commander extension versions 5.0.0 through 6.1.1. Any site that has installed this extension within the specified version range is at risk, regardless of the Joomla core version. No other products are listed.
Risk and Exploitability
The CVSS score of 5.1 indicates moderate severity, and the EPSS score of less than 1% suggests a relatively low current exploitation probability, although active exploitation cannot be ruled out. The vulnerability can be leveraged by sending a crafted HTTP request or form submission that contains malicious query parameters; the extension then reflects the input without proper encoding, exposing the user’s browser to script execution.
OpenCVE Enrichment