Web / CMS

Cross-Site Scripting (XSS)

Extension - advcomsys.com - XSS in oneVote component for Joomla <= 1.7.0

Successful exploitation allows an attacker to craft malicious input that executes JavaScript in a victim's browser if the victim interacts with the malicious content.

6.1
/ 10
Medium
CVSS v3.1
ADVISORY ID
PS105
PUBLISHED
2026-07-08
CVE IDs
CVE-2023-23756
VENDORS
Onevote (advcomsys.com)
PUBLIC EXPLOIT
None indexed
CWE
CWE-79
PRODUCT
oneVote component for Joomla
CVSS VECTOR
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Abstract blurred background with dark tones and smooth gradient waves of blue, purple, and orange hues.
Summary

Overview

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in advcomsys.com oneVote component for Joomla. It allows XSS Targeting Non-Script Elements.

Vulnerability details

Vulnerability details

CVE-2023-23756
CWE-79
Medium | 6.1

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in advcomsys.com oneVote component for Joomla. It allows XSS Targeting Non-Script Elements.

Auth:
None (remote, user interaction required)
Impact:
Limited data disclosure, limited data tampering; impact extends beyond the vulnerable component
Impact

What an attacker can do

Successful exploitation allows an attacker to craft malicious input that executes JavaScript in a victim's browser if the victim interacts with the malicious content. This can lead to session hijacking, credential theft, or unauthorized actions performed in the victim's browser context.

DISCLOSURE

Disclosure timeline

2023-05-17 Issue raised

2023-07-11 Published

Credits

Payatu's Secure Code Review Tower