Impact
The vulnerability is an XSS flaw that originates from improper escaping of schema.org markup generated by Joomla! CMS. When a page containing the vulnerable output is rendered, an attacker can inject malicious scripts that execute in the browsers of the visitors. Potential outcomes such as session cookie theft or page defacement are plausible because they are typical consequences of XSS, but the advisory does not explicitly state these effects; they are inferred from the nature of the vulnerability. This weakness is identified as CWE‑79.
Affected Systems
All Joomla! CMS installations running any of the Joomla core versions 5.1.0 through 5.4.7 or 6.0.0 through 6.1.2 are affected. The flaw resides in the core product and does not involve any third‑party extensions.
Risk and Exploitability
The CVSS base score of 5.1 categorises the issue as moderate. No EPSS score is available, so the likelihood of exploitation is uncertain, and the advisory is not listed in the CISA KEV catalogue, indicating no widespread exploitation has been reported. The attack vector most likely involves a user visiting a page that contains the vulnerable schema.org markup, such as via a drive‑by visit or a crafted link, leading to script execution in the victim’s browser. The impact remains confined to the client side; the server remains unexploited.
OpenCVE Enrichment