Vulnerability Description
Joomla VirtueMart Shopping-Cart 4.0.12 contains a reflected cross-site scripting vulnerability that allows attackers to inject malicious scripts by manipulating the keyword parameter. Attackers can craft malicious URLs containing script payloads in the keyword parameter of the product-variants endpoint to execute arbitrary JavaScript in victim browsers and steal session tokens or credentials.
CVSS Score
MEDIUM
Related Weaknesses (CWE)
References
- https://demo.virtuemart.net/
- https://www.exploit-db.com/exploits/51631
- https://www.virtuemart.net/
- https://www.vulncheck.com/advisories/joomla-virtuemart-shopping-cart-reflected-x
FAQ
What is CVE-2023-54362?
CVE-2023-54362 is a vulnerability with a CVSS score of 6.1 (MEDIUM). Joomla VirtueMart Shopping-Cart 4.0.12 contains a reflected cross-site scripting vulnerability that allows attackers to inject malicious scripts by manipulating the keyword parameter. Attackers can cr...
How severe is CVE-2023-54362?
CVE-2023-54362 has been rated MEDIUM with a CVSS base score of 6.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2023-54362?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.