Impact
The vulnerability allows an attacker to embed malicious JavaScript into the search GET parameter of the Phoca Download extension for Joomla. When the query string is reflected unescaped in the page, any user who follows a crafted link will have that script executed in their browser. The impact is limited to the victim’s session context but can lead to cookie theft, session hijacking or malicious redirects.
Affected Systems
Any Joomla site that has the Phoca Download extension installed in versions 5.0.0 through 6.1.4 is affected. The attack does not require elevated privileges or local access, only delivery of a malicious URL to a user.
Risk and Exploitability
The CVSS score of 5.3 indicates a medium severity. The EPSS score of less than 1% signals a low probability of exploitation in the wild, and the vulnerability is not yet listed in CISA’s KEV catalog. The likely attack vector is a social‑engineering campaign or a malicious link in an e‑mail or comment, which when viewed by a Joomla site visitor, triggers the reflected script. Because the flaw relies on injection of unsanitised user input, an attacker can execute arbitrary JavaScript in the victim’s browser without needing any privileged access.
OpenCVE Enrichment