Web / CMS
Cross-Site Scripting (XSS)
Extension - advcomsys.com - XSS in oneVote component for Joomla <= 1.7.0
Successful exploitation allows an attacker to craft malicious input that executes JavaScript in a victim's browser if the victim interacts with the malicious content.
.png)
Overview
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in advcomsys.com oneVote component for Joomla. It allows XSS Targeting Non-Script Elements.
Vulnerability details
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in advcomsys.com oneVote component for Joomla. It allows XSS Targeting Non-Script Elements.
What an attacker can do
Successful exploitation allows an attacker to craft malicious input that executes JavaScript in a victim's browser if the victim interacts with the malicious content. This can lead to session hijacking, credential theft, or unauthorized actions performed in the victim's browser context.
Disclosure timeline
2023-05-17 Issue raised
2023-07-11 Published
References
Credits
Payatu's Secure Code Review Tower
















