Executive brief
JoomShopping, a popular e-commerce extension for the Joomla content management system, contains a security flaw that could allow attackers to execute malicious scripts in a user's browser. By tricking a user into clicking a specially crafted link, an attacker could potentially steal session information or perform unauthorized actions on behalf of the user. This impact is generally limited to the user's interaction with the online store frontend.
Technical details
A reflected cross-site scripting (XSS) vulnerability exists in the JoomShopping extension for Joomla (versions 1.0.0 through 5.9.2) within the product frontend controller. The flaw stems from improper neutralization of user-supplied input during web page generation (CWE-79). An unauthenticated remote attacker can exploit this by persuading a user to visit a malicious URL, leading to the execution of arbitrary JavaScript in the context of the victim's browser session. This can result in unauthorized access to session tokens or sensitive information displayed on the page.
Affected products
- joomshopping.com JoomShopping extension for Joomla 1.0.0-5.9.2
Timeline
- 2026-07-22: advisory: NVD publication date