Impact
A reflected cross‑site scripting flaw and an open redirect are present in the Zoo extension for Joomla when the submission redirect parameter is not sanitized. The vulnerability allows an attacker to inject arbitrary JavaScript that is executed in the context of the victim’s browser, and simultaneously redirect the victim to an arbitrary external site. An attacker can therefore lure users to phishing sites, steal session cookies, or execute further malicious actions in the victim’s browser. This directly compromises the confidentiality and integrity of the data accessed through the Joomla instance, and can be used as a vector for social‑engineering attacks that impact system availability in the sense that trusted user interactions are subverted.
Affected Systems
The Zoo extension from yootheme.com for Joomla versions prior to 4.1.66 is affected. The vulnerability is tied to the handling of the submission redirect parameter in those releases.
Risk and Exploitability
The CVSS score of 5.3 shows moderate severity. No EPSS score is publicly available, and the vulnerability is not listed in the CISA KEV catalog. The flaw is triggered by a reflected parameter that can be crafted via a URL or form input; therefore an external attacker with the ability to persuade a Joomla site visitor to access the crafted URL can exploit the issue. The attack path is straightforward, no special privileges are required, and the impact can be widespread if the affected Joomla site is widely visited.
OpenCVE Enrichment