Impact
The Quick Index extension for Joomla allows configuration of a CSS class that is inserted directly into generated HTML. The option value is not escaped, so a crafted input can close the class attribute and inject a new attribute, permitting arbitrary script to be stored and executed whenever the page is viewed. This stored cross‑site scripting vulnerability (CWE‑79) provides attackers with the ability to steal session cookies, hijack user sessions, a privileged user (e.g., an administrator or content author) injects the payload.
Affected Systems
The vulnerability affects both the Free and Pro versions of the Quick Index extension sold by regularlabs.com for Joomla platforms running any version All sites that have installed Quick Index before the 5.0.5 release are potentially impacted.
Risk and Exploitability
Because the flaw is stored, an attacker must first be able to insert the malicious value via the extension’s administrative interface, which typically requires at least content‑author privileges. Once the payload is stored, it is rendered in the browser of any user who views the affected page, enabling cross‑site scripting without additional user interaction. The CVSS score of 7.5, EPSS score of 0.00247 (<1%) indicates a very low but non‑zero exploitation probability, and the vulnerability is not listed in the CISA KEV catalog, suggesting no widespread exploitation yet but a still significant risk based on the potential impact and required privileges.
OpenCVE Enrichment