Web / CMS
Cross-Site Scripting (XSS)
Extplorer Component up to 2.1.15 on Joomla cross site scripting
Successful exploitation allows an attacker to inject malicious JavaScript into a specially crafted URL.
.png)
Overview
A vulnerability has been found in Extplorer Component up to 2.1.15 on Joomla (Joomla Component) and classified as problematic. This vulnerability affects some unknown functionality. The manipulation with an unknown input leads to a cross site scripting vulnerability. The CWE definition for the vulnerability is CWE-79. The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users. As an impact it is known to affect integrity.
Vulnerability details
A vulnerability has been found in Extplorer Component up to 2.1.15 on Joomla (Joomla Component) and classified as problematic. This vulnerability affects some unknown functionality.
What an attacker can do
Successful exploitation allows an attacker to inject malicious JavaScript into a specially crafted URL. If a victim (such as an administrator or authenticated user) clicks the malicious link, the script executes in the victim's browser under the context of the vulnerable Joomla site.
Disclosure timeline
2023-05-17 Issue raised on github
2023-12-14 Published
Reported to Vendor
References
2026-06-17 (NVD record)
Credits
Payatu's Secure Code Review Tower
















