Impact
The vulnerability is a reflected Cross‑Site Scripting flaw in Phoca Cart for Joomla. An attacker can embed malicious script payloads via the price_from and price_to query parameters. When a vulnerable site loads the URL, the unescaped user supplied input appears in the response, allowing an attacker to run JavaScript in the user’s browser. The flaw is categorized as CWE‑79 and could enable cookie theft, defacement, or session hijack for anyone visiting the infected page.
Affected Systems
All Joomla installations that use the Phoca Cart extension with a version between 5.0.0 and 6.1.7 inclusive are affected. The vendor is phoca.cz. The extension functions as an e‑commerce add‑on for Joomla websites.
Risk and Exploitability
The CVSS score of 5.3 indicates moderate overall risk. The EPSS score of less than 1% points to a very low probability of exploitation in the wild, and the vulnerability is not listed in CISA’s KEV catalog. The most likely attack vector is through crafted URL requests that an unsuspecting site visitor or an attacker‑controlled link might follow. Because the flaw operates in the browser, it requires an active user context to cause damage.
OpenCVE Enrichment