Impact
The vulnerability arises from unsanitized storage of the HTTP User‑Agent header in the Phoca Cart admin Order view. An attacker can supply a payload in the User‑Agent field that will be rendered when an administrator opens the order page, leading to stored XSS. This can compromise the administrator’s session or deface the CMS interface. The weakness is a classic web‑app input validation flaw (CWE‑79).
Affected Systems
The flaw affects the phoca.cz Phoca Cart extension for Joomla. Any installation that includes Phoca Cart versions from 5.0.0 through 6.1.7 is vulnerable.
Risk and Exploitability
The CVSS score of 8.6 indicates a high‑severity flaw. The EPSS score is below 1 %, suggesting low likelihood of widespread exploitation at present. The issue is not listed in CISA’s KEV catalog, so no widespread campaigns are known. An attacker would need to control the User‑Agent header, which is possible via HTTP requests they can generate. The exploit requires an authenticated administrator to view the affected page, which limits the attack surface but still offers a direct path for malicious script execution inside privileged sessions.
OpenCVE Enrichment