Impact
The vulnerability allows an attacker to inject unescaped data from a visitor‑controlled request into the output of the Articles Anywhere and Users Anywhere extensions. Because the extensions return request‑input tagization, the data may be rendered as executable JavaScript, an event attribute, or a malicious URL. This flaw is a classic reflected XSS. The attacker can execute arbitrary script in the victim’s browser, enabling session hijacking, defacement, phishing, or other client‑side compromise.
Affected Systems
Affected are the Articles Anywhere Pro and Users Anywhere Pro extensions for Joomla from regularlabs.com. Users running Articles Anywhere in Joomla versions older than 20.0.0 and Users Anywhere in Joomla versions older than 2.1.0 are vulnerable. The flaw originates in the extensions’ handling of request‑input data tags that are not marked safe for the output context.
Risk and Exploitability
The CVSS score of 5.3 indicates moderate severity. The EPSS score of <1% suggests a low overall exploitation probability, yet the flaw remains exploitable by any unauthenticated visitor with a crafted URL or form submission. The vulnerability is not listed in the CISA KEV catalog, so widespread exploitation is not confirmed. The most likely attack vector is a web browser visit to a page that utilizes one of the vulnerable extensions and includes a crafted request‑input tag value.
OpenCVE Enrichment