Vulnerability
A vulnerability has been found in Extplorer Component up to 2.1.15 on Joomla (Joomla Component) and classified as problematic. This vulnerability affects some unknown functionality. The manipulation with an unknown input leads to a cross site scripting vulnerability. The CWE definition for the vulnerability is CWE-79. The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users. As an impact it is known to affect integrity.
Impact
Successful exploitation allows an attacker to inject malicious JavaScript into a specially crafted URL. If a victim (such as an administrator or authenticated user) clicks the malicious link, the script executes in the victim’s browser under the context of the vulnerable Joomla site.
CVE ID – CVE-2023-40628
Vendor – Extplorer.net
Product – Extplorer component for Joomla
CVSS Score
Base score – 6.1
CVSS Base vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Diclosure Timeline –
2023-05-17 – Issue raised on github
2023-12-14 – Published
– Reported to Vendor
Credits
Payatu’s Secure Code Review Tower