Executive brief
Phoca Commander, a file management tool for the Joomla content management system, contains a security flaw that could allow attackers to execute malicious scripts in a user's browser. This occurs when a user clicks a specially crafted link, potentially allowing the attacker to perform actions on behalf of the user or access sensitive session information within the Joomla administration interface. The vulnerability impacts versions 5.0.0 through 6.1.1 of the extension.
Technical details
A reflected cross-site scripting (XSS) vulnerability exists in the Phoca Commander extension for Joomla, versions 5.0.0 through 6.1.1. The issue stems from improper neutralization of user-supplied input during web page generation (CWE-79). An unauthenticated remote attacker can exploit this by tricking a user into clicking a malicious link, leading to the execution of arbitrary JavaScript in the context of the victim's browser session. This could result in unauthorized access to administrative functions or session hijacking. The vulnerability has been assigned a CVSS 4.0 base score of 5.1 by the Joomla! Project.
Affected products
- phoca.cz Phoca Commander extension for Joomla 5.0.0-6.1.1
Timeline
- 2026-07-27: advisory: CVE published by NVD and Joomla! Project