Executive brief
Phoca Guestbook is a popular extension for the Joomla content management system that allows websites to host visitor message boards. A security flaw in versions 1.0.0 through 6.1.0 allows attackers to inject malicious scripts into the website. If a site administrator or visitor clicks a specially crafted link, the attacker could potentially steal session information or perform unauthorized actions on their behalf.
Technical details
A reflected cross-site scripting (XSS) vulnerability exists in the Phoca Guestbook extension (versions 1.0.0-6.1.0) for Joomla. The issue stems from improper neutralization of user-supplied input during web page generation (CWE-79). An unauthenticated remote attacker can exploit this by tricking a user into clicking a malicious link containing crafted parameters. Successful exploitation allows the execution of arbitrary JavaScript in the context of the victim's browser session, which can lead to session hijacking or unauthorized manipulation of the web application.
Affected products
- phoca.cz Phoca Guestbook extension for Joomla 1.0.0-6.1.0
Timeline
- 2026-07-23: disclosed
- 2026-07-23: advisory