Executive brief
Phoca Maps is a Joomla extension used to display Google Maps or OpenStreetMap content on websites. A security vulnerability in versions 1.0.0 through 6.0.9 allows attackers to perform reflected cross-site scripting (XSS) attacks. If a user clicks a malicious link, an attacker could execute unauthorized scripts in the user's browser, potentially leading to session hijacking or the theft of sensitive information.
Technical details
A reflected cross-site scripting (XSS) vulnerability exists in the Phoca Maps extension for Joomla (versions 1.0.0-6.0.9). The vulnerability stems from improper neutralization of user-supplied input during web page generation (CWE-79). An unauthenticated remote attacker can exploit this by tricking a user into visiting a specially crafted URL. Successful exploitation allows the execution of arbitrary JavaScript in the context of the victim's browser session, which can be used to access session tokens or perform actions on behalf of the user. The issue is reported as fixed in versions following 6.0.9.
Affected products
- phoca.cz Phoca Maps extension for Joomla 1.0.0-6.0.9
Timeline
- 2026-07-23: disclosed: Initial disclosure date
- 2026-07-23: advisory: NVD publication date