Impact
The All Video Share extension for Joomla contains a reflected cross‑site scripting flaw. User‑supplied input is returned to the browser without proper escaping, allowing an attacker to inject and execute arbitrary JavaScript when the input is displayed. This can enable data theft, session hijacking or other client‑side attacks.
Affected Systems
The vulnerability affects the All Video Share Joomla extension released by mrvinoth.com, with all versions from 1.0.0 through 4.5.0 susceptible.
Risk and Exploitability
The CVSS score of 5.3 indicates moderate severity. The EPSS score is not available, so exploitation frequency in the wild is unknown. The flaw is not listed in the CISA KEV catalog. An attacker can trigger the issue by submitting malicious input via the extension’s web interface; no special privileges are required.
OpenCVE Enrichment