Web / CMS

Cross-Site Scripting (XSS)

Extplorer Component up to 2.1.15 on Joomla cross site scripting

Successful exploitation allows an attacker to inject malicious JavaScript into a specially crafted URL.

6.1
/ 10
Medium
CVSS v3.1
ADVISORY ID
PS104
PUBLISHED
2026-07-07
CVE IDs
CVE-2023-40628
VENDORS
Extplorer.net
PUBLIC EXPLOIT
None indexed
CWE
CWE-79
PRODUCT
Extplorer component for Joomla
CVSS VECTOR
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Abstract blurred background with dark tones and smooth gradient waves of blue, purple, and orange hues.
Summary

Overview

A vulnerability has been found in Extplorer Component up to 2.1.15 on Joomla (Joomla Component) and classified as problematic. This vulnerability affects some unknown functionality. The manipulation with an unknown input leads to a cross site scripting vulnerability. The CWE definition for the vulnerability is CWE-79. The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users. As an impact it is known to affect integrity.

Vulnerability details

Vulnerability details

CVE-2023-40628
CWE-79
Medium | 6.1

A vulnerability has been found in Extplorer Component up to 2.1.15 on Joomla (Joomla Component) and classified as problematic. This vulnerability affects some unknown functionality.

Auth:
None (remote, user interaction required)
Impact:
Limited data disclosure, limited data tampering; impact extends beyond the vulnerable component
Impact

What an attacker can do

Successful exploitation allows an attacker to inject malicious JavaScript into a specially crafted URL. If a victim (such as an administrator or authenticated user) clicks the malicious link, the script executes in the victim's browser under the context of the vulnerable Joomla site.

DISCLOSURE

Disclosure timeline

2023-05-17 Issue raised on github

2023-12-14 Published

Reported to Vendor

Credits

Payatu's Secure Code Review Tower