Executive brief
Phoca Download is a Joomla extension for managing downloadable files and content. A reflected cross-site scripting (XSS) vulnerability in the search function allows attackers to inject malicious scripts that execute in users' browsers when they click a crafted link, potentially compromising user sessions or redirecting visitors to malicious sites.
Technical details
A reflected XSS vulnerability exists in Phoca Download versions 5.0.0 through 6.1.4 in the search GET parameter. The vulnerability occurs because user-supplied input from the search parameter is not properly sanitized or encoded before being reflected in the HTTP response. An attacker can craft a malicious URL containing JavaScript code in the search parameter, and when a victim visits the link, the script executes in their browser with the context of the vulnerable application. No authentication is required, and the attack vector is network-based via a crafted URL. A patch is likely available in versions later than 6.1.4.
Affected products
- phoca.cz Phoca Download 5.0.0-6.1.4
Timeline
- 2026-08-20: disclosed