Impact
This vulnerability is a reflected cross‑site scripting flaw in the Joomdle component for Joomla versions earlier than 3.1.1. The flaw lies in the goto url parameter of the moodle wrapper endpoint, allowing an attacker to inject arbitrary JavaScript that is immediately reflected back to the victim’s browser. A crafted link could lead the victim’s browser to execute malicious code in the context of the user, enabling session theft, phishing, or other client‑side attacks. The weakness is identified as CWE‑79.
Affected Systems
The impacted product is the Joomdle component for Joomla distributed by joomdle.com. All installations using Joomdle versions before 3.1.1 are susceptible. No other products or vendors are listed.
Risk and Exploitability
The CVSS v3.1 score of 6.1 indicates a moderate severity. The EPSS score of less than 1 % suggests the likelihood of exploitation is low, and it is not currently listed in the CISA KEV catalog. The most probable attack vector is a remote web user delivering a crafted link that exploits the goto url parameter; authentication or privileged access is not required, making the vulnerability broadly exploitable.
OpenCVE Enrichment